Vulnerability
Stored Cross Site Scripting (XSS) in Simple Share Plugin <=0.5.3
Description
The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-ID
CVE-2024-7556
Vendor
WordPress
Product
Simple Share Plugin
Disclosure Timeline
Made Public On: 07-09-2024
Reported On 10-08-2024
Fixed On: Not Fixed
Credits
Amandeep Singh Banga