Impact
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to reflected cross‑site scripting in all releases up to 3.0.1. Insufficient input sanitization and output escaping allows an unauthenticated attacker to embed arbitrary JavaScript in the URL that is reflected back to the page when the user accesses the link. Once executed, the injected script runs in the context of the victim’s browser and can steal cookies, deface content, or perform further malicious actions.
Affected Systems
WordPress sites running the inisev Social Media Share Buttons & Social Sharing Icons plugin version 3.0.1 or earlier are affected. The vulnerability is present in all earlier releases of the plugin.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium impact and requires no special privileges; the attacker does not need to be authenticated. Exploitation is tailored to mobile users who click the WeChat share icon – a user‑agent check and a single click are the only prerequisites. After the share dialog opens, the injected script executes automatically without further interaction. Although the EPSS score is not available and the weakness is not in the CISA KEV catalog, the reliance on a common social‑sharing workflow makes this vector readily available to attackers. Accordingly, the overall risk remains moderate but nontrivial for organizations that deploy the vulnerable plugin version.
OpenCVE Enrichment