WordPress Plugin Vulnerabilities

Simple Social Media Share Buttons < 3.2.3 - Contributor+ Stored XSS

Description

The plugin did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
apple502j
Submitter
apple502j
Verified
Yes

Timeline

Publicly Published
2021-07-26 (about 4 years ago)
Added
2021-07-26 (about 4 years ago)
Last Updated
2022-02-24 (about 3 years ago)

Other