CVE-2024-2836: Super Socializer < 7.13.64 - Editor+ Stored XSS
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2836?
CVE-2024-2836 is classified as a high severity vulnerability due to its potential for Cross-Site Scripting attacks by high privilege users.
How do I fix CVE-2024-2836?
To fix CVE-2024-2836, update the Social Share, Social Login and Social Comments Plugin to version 7.13.64 or later.
Who is affected by CVE-2024-2836?
CVE-2024-2836 affects users of the Social Share, Social Login and Social Comments Plugin for WordPress versions before 7.13.64.
What are the consequences of CVE-2024-2836?
The consequences of CVE-2024-2836 include the risk of unauthorized Cross-Site Scripting attacks, potentially compromising web applications.
Is CVE-2024-2836 exploitable in all WordPress installations?
CVE-2024-2836 is exploitable specifically in installations with the vulnerable version of the affected plugin, typically when high privilege users have access.