ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-4434
The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter.

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.

NVD description · AI analysis pending
9.82% PoC
  • warfareplugins social warfare
CVE-2023-4842
The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, a

The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4<1%
  • warfareplugins social warfare
CVE-2023-0402
+1 in the same advisory: …0403
The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and i

The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset network access tokens.

NVD description · AI analysis pending
5.4<1% PoC
  • warfareplugins social warfare
CVE-2019-9978
Stored XSS in WordPress Social Warfare Plugin (CVE-2019-9978) Exploited in the Wild

CVE-2019-9978 is a stored cross-site scripting (CWE-79) flaw in the Social Warfare social-sharing plugin for WordPress: the plugin's debug routine at wp-admin/admin-post.php?swp_debug=load_options accepts an unauthenticated swp_url parameter and uses it to pull in attacker-controlled settings/content that is then persisted on the site. An attacker triggers the flaw by simply sending an unauthenticated request to admin-post.php with swp_debug=load_options and a crafted swp_url; the injected content later executes in the browsers of WordPress administrators when they view the affected dashboard or pages. Successful exploitation lets an attacker run arbitrary JavaScript in admin sessions, change plugin and site settings, and inject malicious scripts, redirects, or content into the site; public PoCs and the in-the-wild exploits were described as escalating to remote code execution. Any WordPress site running Social Warfare or Social Warfare Pro before version 3.5.3 is affected. The flaw was exploited as a zero-day in March 2019, is on CISA's KEV (added 2021-11-03) with a 72.9% EPSS (99th percentile), and related reporting indicates widespread active exploitation with follow-on web shell activity.

Do: Upgrade Social Warfare and Social Warfare Pro to version 3.5.3 or later immediately (apply updates per vendor instructions) and verify the installed version under Plugins in wp-admin. If updating is not possible right away, deactivate the plugin or block unauthenticated requests to admin-post.php that include the swp_debug parameter. Review plugin settings, posts, and pages for injected JavaScript, check administrator accounts for additions or changes, and hunt for web shells given reported follow-on deployments.

6.173% KEV PoC ×5
  • warfareplugins Social Warfare (WordPress plugin) before 3.5.3
  • warfareplugins Social Warfare Pro (WordPress plugin) before 3.5.3
largeroughly tens of thousands of sites (≈60,000–70,000 WordPress installs at the time of the March 2019 disclosure)