CVE-2026-19719: Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Contributor+ Stored XSS via Post Title

Published Sep 2, 2026
·
Updated

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.

Affected Software

1 affected component
WordPress Social Media Share Buttons & Social Sharing Icons<3.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade wordpress/Social Media Share Buttons & Social Sharing Icons to a version that resolves this vulnerability.

    Fixed in 3.0.1
  2. Compensating control

    Ensure the Social Media Share Buttons & Social Sharing Icons WordPress plugin is not running with a non-default icon display configuration, since exploitation requires a non-default icon display configuration.

Event History

Sep 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description

Frequently Asked Questions

1

Who can exploit this issue?

A user with the WordPress Contributor role or any higher-privileged role can exploit the issue by using a crafted post title.

2

Are default plugin settings affected?

Exploitation requires a non-default icon display configuration. The issue is not exploitable under the plugin's default icon display configuration based on the available information.

3

When is the injected script triggered?

The stored script is triggered when a visitor interacts with the affected social-sharing button.

4

What version should be used to remediate the issue?

Update the Social Media Share Buttons & Social Sharing Icons plugin to version 3.0.1 or later. The vulnerability affects versions before 3.0.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203