Description
Unauthenticated Cross Site Scripting (XSS) in Social Share Icons & Social Share Buttons <= 3.7.5 versions.
Published: 2026-10-10
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Unauthenticated Cross Site Scripting (XSS) is present in the Social Share Icons & Social Share Buttons plugin for WordPress versions 3.7.5 and earlier. The flaw allows an attacker to inject and execute arbitrary scripts in the context of a victim’s browser. An attacker who can craft or influence content displayed by the plugin—such as a special URL or form payload—can cause the victim to run malicious JavaScript, potentially leading to session hijacking, defacement, or phishing attacks. The weakness is a classic stored or reflected XSS, as identified by CWE‑79.

Affected Systems

The vulnerability affects the Inisev Social Share Icons & Social Share Buttons WordPress plugin. All releases up to and including version 3.7.5 are impacted. No additional version information is provided, so any installation with a version number 3.7.5 or lower should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity level. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires no authentication; the attacker merely needs to deliver a crafted request to a page that loads the plugin. Because the flaw is an XSS and the vector is public, it is reasonably exploitable from the web, especially on sites that allow untrusted content input or use the plugin on publicly exposed pages.

Generated by OpenCVE AI on October 10, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Social Share Icons & Social Share Buttons plugin to a version newer than 3.7.5 if a fixed release is available.
  • If no newer release exists, remove the plugin entirely or disable all features that allow arbitrary content rendering.
  • Ensure that any user‑supplied content processed by the plugin is properly sanitized or escaped to mitigate XSS risk.

Generated by OpenCVE AI on October 10, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Social Share Icons & Social Share Buttons <= 3.7.5 versions.
Title WordPress Social Share Icons & Social Share Buttons plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:09.276Z

Reserved: 2026-04-29T09:05:01.790Z

Link: CVE-2026-42697

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:35.433

Modified: 2026-10-10T20:16:35.433

Link: CVE-2026-42697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T20:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')