๐Ÿ” CVE Alert

CVE-2026-19719

UNKNOWN 0.0

Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Contributor+ Stored XSS via Post Title

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.

Vendor unknown
Product social media share buttons & social sharing icons
Published Sep 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown social media share buttons & social sharing icons

Be the first to know when new unknown vulnerabilities affecting unknown social media share buttons & social sharing icons are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Social Media Share Buttons & Social Sharing Icons
0 < 3.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c2f7987b-8cac-4c02-97f7-b33bea5b5cc4/

Credits

Mohammed Abd Alrahman WPScan