medium · CVSS v3 4.4 · EPSS 0.00208
CVE-2026-12042
The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) within its administrative settings. This
Overview
The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) within its administrative settings. This vulnerability exists in all versions up to 2.4.12 due to inadequate input sanitization and output escaping of user-provided data.
Description
The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Impact
Successful exploitation allows high-privileged users to execute arbitrary scripts in the browser sessions of other administrators. This impacts the integrity and confidentiality of the administrative interface, particularly in multi-site WordPress environments or those with restricted HTML capabilities. The risk is primarily focused on session hijacking or unauthorized configuration changes within the management console.
Remediation
Update the WP2Social Auto Publish plugin to the latest available version (greater than 2.4.12) to ensure proper sanitization routines are in place. Administrators should also review plugin settings for any unauthorized script tags and verify that the 'unfiltered_html' capability is restricted to trusted users only.
Risk context
The vulnerability is rated as Medium severity with a CVSS score of 4.4. The low EPSS score of 0.00208 suggests a low probability of current active exploitation in the wild, largely because the flaw requires administrator-level privileges to execute.
Affected products
- WP2Social Auto Publish (WordPress Plugin)
Scores
- Severity
- medium
- CVSS v2
- 3.2
- CVSS v3
- 4.4
- CVSS v4
- —
- EPSS
- 0.00208