Impact
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before version 3.0.1 fails to escape the post title before inserting it into an inline JavaScript event handler. This omission allows any user with the Contributor role or higher to store malicious script content in a post title. When a visitor interacts with the affected share button, the unescaped title is executed as JavaScript, enabling Stored Cross‑Site Scripting that can compromise visitor privacy, steal session data, or perform arbitrary actions in the site context.
Affected Systems
WordPress sites running the Social Media Share Buttons & Social Sharing Icons plugin in any version earlier than 3.0.1 are affected. The flaw appears only when the plugin is configured to use a non‑default icon display setting. The plugin is distributed by an unknown vendor but is widely deployed through the WordPress plugin ecosystem.
Risk and Exploitability
The flaw carries a CVSS score of 6.8, indicating a moderate severity that can lead to stored cross‑site scripting when a contributor inserts malicious JavaScript into a post title. An attacker must have Contributor or higher permissions to embed the payload, but once the plugin processes a visitor’s interaction with the affected share button, the unescaped title is executed as inline JavaScript. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the public exploitation likelihood remains uncertain; however, the presence of a non‑default icon display configuration is the only additional prerequisite for the attack chain.
OpenCVE Enrichment