All vulnerabilities
CVE-2026-19719 Medium CVSS 6.8

Social Media Share Buttons & Social Sharing Icons — Contributor+ Stored XSS via Post Title

Vendor UltimatelySocial
Product Social Media Share Buttons & Social Sharing Icons (Ultimate Social Media Icons)
Affected versions < 3.0.1
Weakness CWE-79
CVSS vector CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Reported 2026-08-13
Disclosed 2026-08-31
Status Published
The plugin fails to escape the post title before outputting it inside an inline JavaScript event handler, allowing users with the Contributor role or above to inject Stored XSS that triggers when a visitor interacts with the affected share button. Exploitation requires a non-default icon display configuration.

Impact

A low-privileged authenticated user (Contributor+) can plant malicious script in a post title that executes in the browser of any visitor or higher-privileged user (editor/admin) who views the affected share button - enabling privilege escalation via session hijacking, admin account takeover, or backdoor injection if triggered by an administrator.