CVE-2024-2118: Social Media Share Buttons < 2.8.9 - Admin+ Stored XSS via settings
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2118?
CVE-2024-2118 has a high severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2118?
To fix CVE-2024-2118, update the Social Media Share Buttons & Social Sharing Icons plugin to version 2.8.9 or later.
Who is affected by CVE-2024-2118?
CVE-2024-2118 affects users of the Social Media Share Buttons & Social Sharing Icons plugin prior to version 2.8.9.
What types of attacks can CVE-2024-2118 enable?
CVE-2024-2118 can enable high privilege users, such as administrators, to perform Stored Cross-Site Scripting attacks.
What versions of the plugin are vulnerable to CVE-2024-2118?
Versions of the Social Media Share Buttons & Social Sharing Icons plugin prior to 2.8.9 are vulnerable to CVE-2024-2118.