Impact
Unauthenticated Cross Site Scripting has been disclosed in the WordPress Social Media & Share Icons plugin for versions 2.9.9 and earlier. The flaw allows an attacker to inject arbitrary JavaScript into web pages served by sites that use the plugin, leading to the execution of malicious scripts in the browsers of any visitors. This can result in session hijacking, theft of credentials, defacement, or redirection to phishing pages, compromising user confidentiality, integrity, and availability of the affected site.
Affected Systems
The vulnerability affects the Inisev Social Media & Share Icons WordPress plugin. Any WordPress site with the plugin installed in a version equal to or less than 2.9.9 is impacted. The plugin should be updated to at least 3.0.0 to obtain the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. Because the vulnerability is unauthenticated, any visitor to an affected site can exploit it; the exploitation requires only loading the compromised page, which is trivial for an attacker. EPSS data is not available, so the exact likelihood is unclear, but the absence of a KEV listing does not eliminate risk. The attack vector is a web browser, making the exploit possible for anyone interacting with the site.
OpenCVE Enrichment