Impact
The vulnerability allows an authenticated administrator to save arbitrary JavaScript through the 'pages' field in the plugin’s admin settings. The malicious code is stored and executed whenever any visitor loads a page that includes the injected content, leading to potential theft of session cookies, credential leakage, or malicious redirects. Because the attacker needs administrator privileges, the impact is limited to users who already have such access, but the stored nature of the flaw means that all subsequent site visitors can be affected.
Affected Systems
Any WordPress installation that has the f1logic:WP2Social Auto Publish plugin version 2.4.12 or older enabled on a multi‑site network, and where the unfiltered_html option is disabled, is vulnerable. The flaw resides in the plugin’s admin Ajax actions and settings pages, so only environments using these components are impacted.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate risk. EPSS is not available, and the flaw is not yet listed in CISA’s KEV catalog. The attack vector is inferred to be an authenticated administrator role, with the necessity of authoring content in the plugin’s ‘pages’ configuration. Once the script is inserted, any user accessing the affected page will trigger execution, meaning the exploit does not require additional privileges beyond the initial admin account.
OpenCVE Enrichment