Vulnerabilities (CVE)

Filtered by vendor Warfareplugins Subscribe
Filtered by product Social Warfare
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-4434 1 Warfareplugins 1 Social Warfare 2024-10-21 N/A 9.8 CRITICAL
The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.
CVE-2019-9978 1 Warfareplugins 2 Social Warfare, Social Warfare Pro 2024-07-25 4.3 MEDIUM 6.1 MEDIUM
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.