Web / CMS

Cross-Site Scripting (XSS)

Stored Cross Site Scripting (XSS) in WordPress Simple Share Plugin <=0.5.3

Stored Cross Site Scripting (XSS) in Simple Share Plugin <=0.5.3 The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

4.8
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS87
PUBLISHED
2025-08-25
CVE IDs
CVE-2024-7556
VENDORS
Simple Share (WordPress plugin)
PUBLIC EXPLOIT
PoC public
CWE
CWE-79
PRODUCT
Simple Share Plugin
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Stored Cross Site Scripting (XSS) in Simple Share Plugin <=0.5.3

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Vulnerability details

Vulnerability details

CVE-2024-7556
CWE-79
Medium | 4.8

Stored Cross Site Scripting (XSS) in Simple Share Plugin <=0.5.3 The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html

Auth:
Administrative privileges (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2024-09-07 Made Public On

2024-08-10 Reported On

Fixed On: Not Fixed

Credits

Amandeep Singh Banga