๐Ÿ” CVE Alert

CVE-2026-16570

UNKNOWN 0.0

NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callback

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.

Vendor unknown
Product nextscripts: social networks auto-poster
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown nextscripts: social networks auto-poster

Be the first to know when new unknown vulnerabilities affecting unknown nextscripts: social networks auto-poster are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / NextScripts: Social Networks Auto-Poster
0 < 4.4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/25c42ca3-ff25-4b43-a712-2876398d82ab/

Credits

Dmitrii Ignatyev WPScan