CVE-2024-2836

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Configurations

Configuration 1 (hide)

cpe:2.3:a:heateor:super_socializer:*:*:*:*:*:wordpress:*:*

History

08 May 2025, 20:31

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/36f95b19-af74-4c56-9848-8ff270af4723/ - () https://wpscan.com/vulnerability/36f95b19-af74-4c56-9848-8ff270af4723/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:heateor:super_socializer:*:*:*:*:*:wordpress:*:*
First Time Heateor super Socializer
Heateor
CWE CWE-79

21 Nov 2024, 09:10

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/36f95b19-af74-4c56-9848-8ff270af4723/ - () https://wpscan.com/vulnerability/36f95b19-af74-4c56-9848-8ff270af4723/ -

03 Jul 2024, 01:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

15 Apr 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-15 05:15

Updated : 2025-05-08 20:31


NVD link : CVE-2024-2836

Mitre link : CVE-2024-2836

CVE.ORG link : CVE-2024-2836


JSON object : View

Products Affected

heateor

  • super_socializer
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')