CVE-2019-9576: XSS
The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9576?
CVE-2019-9576 is a vulnerability in the Blog2Social plugin before version 5.0.3 for WordPress that allows for XSS attacks.
How can the Blog2Social plugin be exploited to perform XSS attacks?
The vulnerability in the Blog2Social plugin allows an attacker to inject malicious scripts into the wp-admin/admin.php?page=blog2social-ship URL, which can then be executed by unsuspecting users.
What is the severity of CVE-2019-9576?
The severity of CVE-2019-9576 is medium with a CVSS score of 6.1.
How can I fix CVE-2019-9576 on my WordPress site?
To fix CVE-2019-9576, you should update the Blog2Social plugin to version 5.0.3 or later, which includes a patch for the XSS vulnerability.
Are there any additional references or resources about CVE-2019-9576?
Yes, you can find more information about CVE-2019-9576 in the following references: [Link 1](https://lists.openwall.net/full-disclosure/2019/02/05/6), [Link 2](https://security-consulting.icu/blog/2019/02/wordpress-blog2social-xss/), [Link 3](https://wordpress.org/plugins/blog2social/#developers).