All vulnerabilities
CVE-2026-19719
Medium
CVSS 6.8
Social Media Share Buttons & Social Sharing Icons — Contributor+ Stored XSS via Post Title
| Vendor | UltimatelySocial |
|---|---|
| Product | Social Media Share Buttons & Social Sharing Icons (Ultimate Social Media Icons) |
| Affected versions | < 3.0.1 |
| Weakness | CWE-79 |
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
| Reported | 2026-08-13 |
| Disclosed | 2026-08-31 |
| Status | Published |
The plugin fails to escape the post title before outputting it inside an inline JavaScript event handler, allowing users with the Contributor role or above to inject Stored XSS that triggers when a visitor interacts with the affected share button. Exploitation requires a non-default icon display configuration.
Impact
A low-privileged authenticated user (Contributor+) can plant malicious script in a post title that executes in the browser of any visitor or higher-privileged user (editor/admin) who views the affected share button - enabling privilege escalation via session hijacking, admin account takeover, or backdoor injection if triggered by an administrator.