CVE-2024-13615

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Mar 11, 2025

Summary

CVE-2024-13615: The Social Share Buttons plugin by Social Snap for WordPress, versions up to 1.3.6, fails to sanitize and escape certain settings, exposing a Stored Cross-Site Scripting (XSS) vulnerability. This issue potentially enables high-privilege users, including admins, to inject malicious scripts into a website, even when the unfiltered_html capability is disallowed, particularly in multisite setups.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share