Loading
Generated remediation guidance and an executive summary. No account required.
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
Use CWE-79, Warfareplugins vendor hub and Social Warfare product page to widen CVE-2019-9978 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-4434, CVE-2023-4842 and CVE-2023-0403 for nearby disclosures in the same product family.