All vulnerabilities
CVE-2026-19723
High
CVSS 7.1
Social Media Share Buttons & Social Sharing Icons — Reflected XSS via Pin It Share Handler
| Vendor | UltimatelySocial |
|---|---|
| Product | Social Media Share Buttons & Social Sharing Icons (Ultimate Social Media Icons) |
| Affected versions | < 3.0.1 |
| Weakness | CWE-79 |
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
| Reported | 2026-08-13 |
| Disclosed | 2026-08-31 |
| Status | Published |
The plugin fails to properly escape a value from the incoming request before outputting it inside an inline JavaScript event handler, allowing Reflected XSS when a user interacts with the affected share button. Exploitation requires a non-default icon display configuration.
Impact
An attacker can craft a malicious link that, when clicked by a victim on a site running a vulnerable, non-default configuration, executes arbitrary JavaScript in the victim's browser session — enabling session hijacking, credential theft, or other client-side attacks against site visitors or logged-in users.