Skip to content
COOEY

EXPOSURES › CVE-2019-9978

CVE-2019-9978

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-9978 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

WordPress Social Warfare plugin XSS vulnerability allows remote code execution and is actively exploited in the wild.

The Social Warfare plugin for WordPress contains a cross-site scripting (XSS) vulnerability that enables remote code execution. This flaw is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning it is actively exploited in the wild. Defense-industrial-base organizations must ensure all WordPress plugins are patched immediately to prevent attackers from executing arbitrary code on their web applications.

Shame score — A known XSS vulnerability in a widely used WordPress plugin was actively exploited in the wild, indicating negligent patching and a failure to address a critical flaw that allows remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

SENTIMENT · TRUSTED SOURCES
synthesis mixed -0.20
Vulnerabilities documented in CVE databases and vendor advisories; no direct press condemnation or praise found in provided sources.
cooey ↗ mixed -0.50
Neutral technical disclosure
"WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution."
www.fused.com ↗ mixed -0.30
Neutral technical disclosure
"PPWP through 1.9.21 lets a Contributor or higher store script-capable values in attributes of the ppwp shortcode. Insufficient sanitization and output escaping cause the payload to execute when a visitor opens the affected page."
Neutral technical disclosure
"The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes."
dev.to ↗ mixed -0.10
Neutral data analysis
"Of 8,010 WordPress plugins with a publicly documented vulnerability since 2023 (15,534 vulnerability records in total): 3,780 have been removed from the wordpress.org plugin directory."
app.opencve.io ↗ mixed +0.00
Neutral data listing
freshysites.com ↗ mixed +0.00
Neutral commercial site
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.