EXPOSURES › CVE-2019-9978
CVE-2019-9978
HIGH ⌖ ON CISA KEV · EXPLOITEDWordPress Social Warfare plugin XSS vulnerability allows remote code execution and is actively exploited in the wild.
The Social Warfare plugin for WordPress contains a cross-site scripting (XSS) vulnerability that enables remote code execution. This flaw is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning it is actively exploited in the wild. Defense-industrial-base organizations must ensure all WordPress plugins are patched immediately to prevent attackers from executing arbitrary code on their web applications.
Shame score — A known XSS vulnerability in a widely used WordPress plugin was actively exploited in the wild, indicating negligent patching and a failure to address a critical flaw that allows remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
"WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution."
"PPWP through 1.9.21 lets a Contributor or higher store script-capable values in attributes of the ppwp shortcode. Insufficient sanitization and output escaping cause the payload to execute when a visitor opens the affected page."
"The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes."
"Of 8,010 WordPress plugins with a publicly documented vulnerability since 2023 (15,534 vulnerability records in total): 3,780 have been removed from the wordpress.org plugin directory."