CVE-2026-42418: WordPress Social Rocket plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Socialrocket Social Rocket social-rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Social Rocket pluginto a version that resolves this vulnerability.Fixed in 1.3.6
Event History
Frequently Asked Questions
Who can exploit this issue?
The vector is network-accessible and requires no attacker privileges, but exploitation requires user interaction. An attacker would need to induce a user to visit or interact with a crafted request or page.
What versions are affected?
Socialrocket Social Rocket versions through 1.3.5 are affected. The available data does not identify a fixed version.
What is the potential impact if exploitation succeeds?
The vulnerability is a reflected XSS issue with scope changed. The supplied severity vector indicates potential low impact to confidentiality, integrity, and availability.