The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 has a Reflected Cross-Site Scripting vulnerability. This occurs because the plugin does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler. Exploitation of this vulnerability requires a non-default icon display configuration.
MEDIUMSocial Media Share Buttons & Social Sharing IconsCVE published 2026-09-02
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 has a Stored Cross-Site Scripting vulnerability. Users with the Contributor role and above can perform attacks triggered when a visitor interacts with the affected button, requiring a non-default icon display configuration. This vulnerability has a CVSS score of 6.8 and a MEDIUM severity, indicating a moderate level of ris [truncated]