CVE-2024-2836

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:heateor:super_socializer:*:*:*:*:*:wordpress:*:*

History

08 May 2025, 20:31

Type Values Removed Values Added
CPE cpe:2.3:a:heateor:super_socializer:*:*:*:*:*:wordpress:*:*
CWE CWE-79
First Time Heateor
Heateor super Socializer
References () https://wpscan.com/vulnerability/36f95b19-af74-4c56-9848-8ff270af4723/ - () https://wpscan.com/vulnerability/36f95b19-af74-4c56-9848-8ff270af4723/ - Exploit, Third Party Advisory

15 Apr 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-15 05:15

Updated : 2025-05-08 20:31


NVD link : CVE-2024-2836

Mitre link : CVE-2024-2836


JSON object : View

Products Affected

heateor

  • super_socializer
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')