CVE-2024-10362: Social Media Share Buttons < 2.9.0 - Admin+ Stored XSS
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10362?
CVE-2024-10362 is classified as a medium severity vulnerability affecting the Social Media Share Buttons & Social Sharing Icons WordPress plugin.
How do I fix CVE-2024-10362?
To fix CVE-2024-10362, update the Social Media Share Buttons & Social Sharing Icons plugin to version 2.9.1 or later.
What types of attacks can CVE-2024-10362 facilitate?
CVE-2024-10362 can facilitate Stored Cross-Site Scripting attacks performed by high-privilege users.
Who is affected by CVE-2024-10362?
CVE-2024-10362 primarily affects high-privilege users, such as administrators of WordPress sites using the vulnerable plugin.
Which versions of the plugin are affected by CVE-2024-10362?
CVE-2024-10362 affects versions of the Social Media Share Buttons & Social Sharing Icons plugin prior to 2.9.1.