CVE-2021-38356: NextScripts: Social Networks Auto-Poster <= 4.3.20 Reflected Cross-Site Scripting
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $REQUEST['page'] parameter which is echoed out on inc/nxsclasssnap.php by supplying the appropriate value 'nxssnap-post' to load the page in $GET['page'] along with malicious JavaScript in $POST['page'].
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38356?
CVE-2021-38356 has a medium severity, as it allows reflected cross-site scripting attacks.
How do I fix CVE-2021-38356?
To fix CVE-2021-38356, update the NextScripts Social Networks Auto-Poster plugin to version 4.3.21 or later.
Who is affected by CVE-2021-38356?
Any WordPress sites using NextScripts Social Networks Auto-Poster plugin versions up to and including 4.3.20 are affected by CVE-2021-38356.
What type of vulnerability is CVE-2021-38356?
CVE-2021-38356 is a reflected cross-site scripting (XSS) vulnerability.
What can attackers do with CVE-2021-38356?
Attackers can exploit CVE-2021-38356 to inject malicious scripts into web pages viewed by users.