Impact
Unauthenticated Cross Site Scripting (XSS) is present in the Social Share Icons & Social Share Buttons plugin for WordPress versions 3.7.5 and earlier. The flaw allows an attacker to inject and execute arbitrary scripts in the context of a victim’s browser. An attacker who can craft or influence content displayed by the plugin—such as a special URL or form payload—can cause the victim to run malicious JavaScript, potentially leading to session hijacking, defacement, or phishing attacks. The weakness is a classic stored or reflected XSS, as identified by CWE‑79.
Affected Systems
The vulnerability affects the Inisev Social Share Icons & Social Share Buttons WordPress plugin. All releases up to and including version 3.7.5 are impacted. No additional version information is provided, so any installation with a version number 3.7.5 or lower should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity level. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires no authentication; the attacker merely needs to deliver a crafted request to a page that loads the plugin. Because the flaw is an XSS and the vector is public, it is reasonably exploitable from the web, especially on sites that allow untrusted content input or use the plugin on publicly exposed pages.
OpenCVE Enrichment