First published: Tue Jan 28 2025(Updated: )
The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Social Share Buttons | <2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12807 is considered a high severity vulnerability due to its potential for stored Cross-Site Scripting attacks.
To mitigate CVE-2024-12807, update the Social Share Buttons for WordPress plugin to version 2.8 or later where the vulnerability is patched.
Users of the Social Share Buttons for WordPress plugin versions up to 2.7 are affected, particularly those with high privilege roles such as admin.
CVE-2024-12807 allows for Stored Cross-Site Scripting attacks, potentially leading to the execution of malicious scripts on affected sites.
CVE-2024-12807 is specifically relevant to users of the Social Share Buttons plugin, and not all WordPress users are affected.