CVE-2025-64198: WordPress Easy Social Share Buttons plugin < 10.7.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Easy Social Share Buttons easy-social-share-buttons3 allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through < 10.7.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64198?
The severity of CVE-2025-64198 is considered high due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-64198?
To fix CVE-2025-64198, update the Easy Social Share Buttons plugin to version 10.7.1 or later.
What impact does CVE-2025-64198 have on my website?
CVE-2025-64198 can allow attackers to inject malicious scripts into web pages, potentially compromising user data and sessions.
Is CVE-2025-64198 specific to any particular version of the software?
Yes, CVE-2025-64198 affects all versions of Easy Social Share Buttons prior to 10.7.1.
Who is affected by CVE-2025-64198?
Websites using the Easy Social Share Buttons plugin versions less than 10.7.1 are at risk due to CVE-2025-64198.