Description
The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-03-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via shortcode attributes
Action: Patch Plugin
AI Analysis

Impact

The Ed's Social Share plugin for WordPress is susceptible to a stored cross‑site scripting flaw contained in the social_share shortcode. In all releases up to and including version 2.0, attributes supplied to that shortcode are not properly validated or escaped, enabling attackers who are authenticated with contributor level or higher to inject arbitrary JavaScript code. When a user views a page or post containing the malicious shortcode, the embedded script executes in the visitor's browser, potentially allowing defacement, data theft, or session hijacking. This weakness aligns with the Cross‑Site Scripting category defined by CWE‑79.

Affected Systems

Any WordPress site that has the Ed's Social Share plugin installed with a version number 2.0 or older is affected. Site administrators must review current installations, as all contributors or higher users possess the privilege to add or edit posts and pages that may contain the vulnerable shortcode.

Risk and Exploitability

The CVSS v3.1 score of 6.4 places this vulnerability in the moderate severity range. Exploitation requires only authenticated access at the contributor level or higher, which is a common role in many sites, thereby enlarging the potential attack surface. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, and no exploit probability data is available, indicating that the exact likelihood of exploitation is unknown. However, the flaw is straightforward to exploit: an attacker simply inserts malicious content into shortcode attributes, and the payload is stored and executed for every subsequent visitor of that page or post.

Generated by OpenCVE AI on March 21, 2026 at 07:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ed's Social Share plugin to the latest available version (≥ 2.1).
  • If an upgrade cannot be performed, remove the plugin or disable its shortcode functionality.
  • Inspect all posts and pages for unexpected JavaScript code that may have been injected.
  • Limit contributor and higher level permissions to trusted users only.

Generated by OpenCVE AI on March 21, 2026 at 07:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Waianaeboy702
Waianaeboy702 ed's Social Share
Wordpress
Wordpress wordpress
Vendors & Products Waianaeboy702
Waianaeboy702 ed's Social Share
Wordpress
Wordpress wordpress

Sat, 21 Mar 2026 05:30:00 +0000

Type Values Removed Values Added
Description The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Ed's Social Share <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Waianaeboy702 Ed's Social Share
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:29:40.295Z

Reserved: 2026-02-13T21:56:10.147Z

Link: CVE-2026-2501

cve-icon Vulnrichment

Updated: 2026-03-24T14:01:41.777Z

cve-icon NVD

Status : Deferred

Published: 2026-03-21T04:17:06.630

Modified: 2026-04-22T21:32:08.360

Link: CVE-2026-2501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:41:24Z

Weaknesses