Description
The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vithanhlam_zsocial_save_messager’, 'vithanhlam_zsocial_save_zalo', 'vithanhlam_zsocial_save_hotline', and 'vithanhlam_zsocial_save_contact' parameters in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Published: 2025-11-25
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting with administrative privileges
Action: Update Plugin
AI Analysis

Impact

The Zweb Social Mobile plugin for WordPress is vulnerable to stored cross‑site scripting through several admin‑only parameters. An attacker who can authenticate as an administrator can submit arbitrary JavaScript that is then saved and rendered on pages accessed by visitors, causing the script to execute whenever those pages are viewed.

Affected Systems

This flaw affects all installations of the Zweb Social Mobile plugin up to and including version 1.0.0 when deployed on WordPress multisite setups that have the unfiltered_html capability disabled. Only users with administrator privileges who have access to the plugin’s configuration pages can perform the injection.

Risk and Exploitability

The CVSS score of 4.4 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires that an attacker first gain administrative access to the site; once the malicious script is stored, it remains active until the plugin is updated or the content is removed.

Generated by OpenCVE AI on April 28, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Zweb Social Mobile plugin to a release newer than 1.0.0 that fixes the input sanitization issue.
  • If an update is unavailable, deactivate or delete the plugin from the multisite network to eliminate stored script vectors.
  • Manually remove or sanitize any content that was entered through the vithanhlam_zsocial_save_* parameters in the plugin’s settings pages.

Generated by OpenCVE AI on April 28, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 25 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Nov 2025 07:45:00 +0000

Type Values Removed Values Added
Description The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vithanhlam_zsocial_save_messager’, 'vithanhlam_zsocial_save_zalo', 'vithanhlam_zsocial_save_hotline', and 'vithanhlam_zsocial_save_contact' parameters in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Title ZWeb - Social Mobile <= 1.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:42:49.139Z

Reserved: 2025-10-21T17:26:33.354Z

Link: CVE-2025-12032

cve-icon Vulnrichment

Updated: 2025-11-25T15:52:16.693Z

cve-icon NVD

Status : Deferred

Published: 2025-11-25T08:15:47.737

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-12032

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:30:29Z

Weaknesses