Generated remediation guidance and an executive summary. No account required.
The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Use CWE-79, Warfareplugins vendor hub and Social Warfare product page to widen CVE-2023-4842 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-9978, CVE-2021-4434 and CVE-2023-0403 for nearby disclosures in the same product family.