CVE-2019-9978

MEDIUM KEV NUCLEI LAB

Social Warfare <3.5.3 - Stored XSS

Title source: llm

Description

The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

Exploits (17)

exploitdb WORKING POC
by Huseyin Mardinli · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52346
exploitdb WORKING POC
by hash3liZer · pythonwebappsphp
https://www.exploit-db.com/exploits/46794
nomisec WORKING POC 22 stars
by hash3liZer · remote
https://github.com/hash3liZer/CVE-2019-9978
nomisec WORKING POC 8 stars
by mpgn · client-side
https://github.com/mpgn/CVE-2019-9978
nomisec WORKING POC 6 stars
by KTN1990 · remote
https://github.com/KTN1990/CVE-2019-9978
nomisec WORKING POC 4 stars
by yup-Ivan · remote
https://github.com/yup-Ivan/CVE-2019-9978
nomisec WORKING POC 3 stars
by grimlockx · remote-auth
https://github.com/grimlockx/CVE-2019-9978
nomisec WORKING POC 2 stars
by d3fudd · remote
https://github.com/d3fudd/CVE-2019-9978_Exploit
nomisec WORKING POC 1 stars
by echoosso · remote
https://github.com/echoosso/CVE-2019-9978
nomisec SUSPICIOUS
by aktia1 · poc
https://github.com/aktia1/MegaQuagga_Pentesting_Report
nomisec WORKING POC
by Vaidehim55 · infoleak
https://github.com/Vaidehim55/CVE-2019-9978-RCE-PoC
nomisec STUB
by xxoprt · poc
https://github.com/xxoprt/payloadCVE-2019-9978
nomisec WORKING POC
by Housma · poc
https://github.com/Housma/CVE-2019-9978-Social-Warfare-WordPress-Plugin-RCE
nomisec WORKING POC
by MAHajian · remote
https://github.com/MAHajian/CVE-2019-9978
nomisec WORKING POC
by h8handles · client-side
https://github.com/h8handles/CVE-2019-9978-Python3
nomisec WORKING POC
by 0xMoonrise · remote
https://github.com/0xMoonrise/cve-2019-9978
nomisec WORKING POC
by cved-sources · poc
https://github.com/cved-sources/cve-2019-9978

Nuclei Templates (1)

WordPress Social Warfare <3.5.3 - Cross-Site Scripting
MEDIUMby madrobot,dwisiswant0
FOFA: body="social-warfare" && body="wp-"

Scores

CVSS v3 6.1
EPSS 0.8765
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull cved/base-wordpress
+11 more repos

Details

CISA KEV 2021-11-03
VulnCheck KEV 2019-03-24
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2019-19332
CWE
CWE-79
Status published
Products (2)
warfareplugins/social_warfare < 3.5.3
warfareplugins/social_warfare_pro < 3.5.3
Published Mar 24, 2019
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026