CVE-2026-16570
NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callback
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a crafted link.
| Vendor | unknown |
| Product | nextscripts: social networks auto-poster |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown nextscripts: social networks auto-poster
Be the first to know when new unknown vulnerabilities affecting unknown nextscripts: social networks auto-poster are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / NextScripts: Social Networks Auto-Poster
0 < 4.4.8
References
Credits
Dmitrii Ignatyev WPScan