All vulnerabilities
CVE-2026-19723 High CVSS 7.1

Social Media Share Buttons & Social Sharing Icons — Reflected XSS via Pin It Share Handler

Vendor UltimatelySocial
Product Social Media Share Buttons & Social Sharing Icons (Ultimate Social Media Icons)
Affected versions < 3.0.1
Weakness CWE-79
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Reported 2026-08-13
Disclosed 2026-08-31
Status Published
The plugin fails to properly escape a value from the incoming request before outputting it inside an inline JavaScript event handler, allowing Reflected XSS when a user interacts with the affected share button. Exploitation requires a non-default icon display configuration.

Impact

An attacker can craft a malicious link that, when clicked by a victim on a site running a vulnerable, non-default configuration, executes arbitrary JavaScript in the victim's browser session — enabling session hijacking, credential theft, or other client-side attacks against site visitors or logged-in users.