Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-4434 | 1 Warfareplugins | 1 Social Warfare | 2024-10-21 | N/A | 9.8 CRITICAL |
The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server. | |||||
CVE-2019-9978 | 1 Warfareplugins | 2 Social Warfare, Social Warfare Pro | 2024-07-25 | 4.3 MEDIUM | 6.1 MEDIUM |
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro. |