rootpwn

medium · CVSS v3 4.4 · EPSS 0.00208

CVE-2026-12042

The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) within its administrative settings. This

Overview

The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) within its administrative settings. This vulnerability exists in all versions up to 2.4.12 due to inadequate input sanitization and output escaping of user-provided data.

Description

The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Impact

Successful exploitation allows high-privileged users to execute arbitrary scripts in the browser sessions of other administrators. This impacts the integrity and confidentiality of the administrative interface, particularly in multi-site WordPress environments or those with restricted HTML capabilities. The risk is primarily focused on session hijacking or unauthorized configuration changes within the management console.

Remediation

Update the WP2Social Auto Publish plugin to the latest available version (greater than 2.4.12) to ensure proper sanitization routines are in place. Administrators should also review plugin settings for any unauthorized script tags and verify that the 'unfiltered_html' capability is restricted to trusted users only.

Risk context

The vulnerability is rated as Medium severity with a CVSS score of 4.4. The low EPSS score of 0.00208 suggests a low probability of current active exploitation in the wild, largely because the flaw requires administrator-level privileges to execute.

Affected products

  • WP2Social Auto Publish (WordPress Plugin)

Scores

Severity
medium
CVSS v2
3.2
CVSS v3
4.4
CVSS v4
EPSS
0.00208

WordPress XSS Stored XSS Plugin WP2Social Administrative

← All CVEs