CVE-2019-9978
24.03.2019, 15:29
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
Vendor | Product | Version |
---|---|---|
warfareplugins | social_warfare | 𝑥 < 3.5.3 |
warfareplugins | social_warfare_pro | 𝑥 < 3.5.3 |
𝑥
= Vulnerable software versions
References