Description
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the victim to be on a mobile user-agent and to click the WeChat share icon, though once the dialog opens, script execution is automatic and requires no further user interaction.
Published: 2026-10-01
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: Reflected XSS enabling arbitrary script execution
Action: Patch Now
AI Analysis

Impact

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to reflected cross‑site scripting in all releases up to 3.0.1. Insufficient input sanitization and output escaping allows an unauthenticated attacker to embed arbitrary JavaScript in the URL that is reflected back to the page when the user accesses the link. Once executed, the injected script runs in the context of the victim’s browser and can steal cookies, deface content, or perform further malicious actions.

Affected Systems

WordPress sites running the inisev Social Media Share Buttons & Social Sharing Icons plugin version 3.0.1 or earlier are affected. The vulnerability is present in all earlier releases of the plugin.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium impact and requires no special privileges; the attacker does not need to be authenticated. Exploitation is tailored to mobile users who click the WeChat share icon – a user‑agent check and a single click are the only prerequisites. After the share dialog opens, the injected script executes automatically without further interaction. Although the EPSS score is not available and the weakness is not in the CISA KEV catalog, the reliance on a common social‑sharing workflow makes this vector readily available to attackers. Accordingly, the overall risk remains moderate but nontrivial for organizations that deploy the vulnerable plugin version.

Generated by OpenCVE AI on October 1, 2026 at 09:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest plugin update (version 3.0.2 or later) to remove the vulnerable code.
  • If the plugin cannot be updated immediately, disable the WeChat share button for mobile user agents so that the vulnerable code path cannot be invoked.
  • Implement a Content Security Policy that disallows inline scripts and restricts script sources to trusted origins, reducing the impact of any remaining injection.

Generated by OpenCVE AI on October 1, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the victim to be on a mobile user-agent and to click the WeChat share icon, though once the dialog opens, script execution is automatic and requires no further user interaction.
Title Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URL
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T07:40:22.379Z

Reserved: 2026-09-10T16:45:45.481Z

Link: CVE-2026-89047

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T08:16:53.187

Modified: 2026-10-01T08:16:53.187

Link: CVE-2026-89047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T09:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')