Showing 1 vulnerability on this page for social_auto_poster

Signals CISA KEV Ransomware Nuclei
wpwebinfotech vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Social Auto Poster <= 5.3.14 - Unauthenticated Stored Cross-Site Scripting

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CWE-79Jul 24, 20241 related artifact
CVSS7.2v3.1EPSS0.822%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX