Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeinity ShareBang, Ultimate Social Share Buttons for WordPress sharebang allows Reflected XSS.This issue affects ShareBang, Ultimate Social Share Buttons for WordPress: from n/a through <= 1.4.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation allows a returned script to be executed in the browser of any visitor who accesses a compromised page. The reflected cross‑site scripting (XSS) flaw can be triggered by an attacker crafting a malicious URL that the ShareBang plugin does not correctly sanitize before echoing back. Once injected, the attacker could steal user credentials, perform actions under the victim’s account, or deliver malware.

Affected Systems

The vulnerability affects the WordPress plugin ShareBang, Ultimate Social Share Buttons for WordPress released by themeinity. All versions up to and including 1.4 are impacted. The issue does not affect newer releases released after 1.4, if any.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, while the EPSS score of less than 1% suggests that active exploitation in the wild is currently unlikely. The flaw is listed in the public advisory but is not part of the CISA KEV catalog. The most probable attack path involves an unauthenticated user clicking a crafted link; no privileged access is required. If exploited, the attacker gains the ability to run arbitrary client‑side code in the context of the victim’s browser session.

Generated by OpenCVE AI on April 29, 2026 at 16:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ShareBang plugin to the latest version that removes the XSS flaw.
  • If an update is not available, temporarily disable or uninstall the plugin to eliminate the attack vector.
  • Implement a Content Security Policy that restricts the execution of inline scripts and blocks the injection of untrusted JavaScript.
  • Apply general WordPress security hardening: keep core, themes, and all plugins updated, use a reputable security plugin, and monitor logs for suspicious activity.

Generated by OpenCVE AI on April 29, 2026 at 16:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Themeinity
Themeinity sharebang
Wordpress
Wordpress wordpress
Vendors & Products Themeinity
Themeinity sharebang
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeinity ShareBang, Ultimate Social Share Buttons for WordPress sharebang allows Reflected XSS.This issue affects ShareBang, Ultimate Social Share Buttons for WordPress: from n/a through <= 1.4.
Title WordPress ShareBang, Ultimate Social Share Buttons for WordPress Plugin <= 1.4 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References

Subscriptions

Themeinity Sharebang
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:28:02.951Z

Reserved: 2025-06-11T16:07:27.326Z

Link: CVE-2025-49953

cve-icon Vulnrichment

Updated: 2025-10-23T15:07:17.733Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:41.747

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-49953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T16:45:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')