CVE-2025-26973: WordPress Social Warfare Plugin <= 4.5.5 - Cross Site Scripting (XSS) vulnerability
Published Feb 22, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WarfarePlugins Social Warfare social-warfare allows DOM-Based XSS.This issue affects Social Warfare: from n/a through <= 4.5.5.
Affected Software
1 affected component
Warfareplugins Social Warfare<=4.5.5
Event History
Feb 22, 2025
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26973?
The severity of CVE-2025-26973 is considered to be moderate due to its potential for DOM-Based Cross-site Scripting (XSS).
2
How do I fix CVE-2025-26973?
To fix CVE-2025-26973, update the WarfarePlugins Social Warfare plugin to version 4.5.5 or later.
3
What are the affected versions of CVE-2025-26973?
CVE-2025-26973 affects WarfarePlugins Social Warfare plugin versions from n/a to 4.5.4.
4
What type of vulnerability is CVE-2025-26973?
CVE-2025-26973 is classified as a Cross-site Scripting (XSS) vulnerability.
5
Who is affected by CVE-2025-26973?
Users of the WarfarePlugins Social Warfare plugin on WordPress are affected by CVE-2025-26973.