CVE-2024-11189: Social Share And Social Locker – ARSocial < 1.4.2 - Admin+ Stored XSS
The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11189?
CVE-2024-11189 is considered a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-11189?
To fix CVE-2024-11189, update the Social Share And Social Locker plugin to version 1.4.2 or later.
Who is affected by CVE-2024-11189?
CVE-2024-11189 affects users of the Social Share And Social Locker plugin for WordPress prior to version 1.4.2.
What types of attacks can be performed due to CVE-2024-11189?
CVE-2024-11189 allows high privilege users to perform stored cross-site scripting attacks.
Is user input handled securely in CVE-2024-11189?
No, CVE-2024-11189 indicates that user input is not properly sanitized and escaped, leading to vulnerabilities.