Medium severity5.4OSV Advisory· Published Mar 6, 2023· Updated Jun 17, 2026
CVE-2023-0377
CVE-2023-0377
Description
The Scriptless Social Sharing WordPress plugin before 3.2.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
30.1.1, 1.0.0, 1.0.1, …+ 1 more
- (no CPE)range: 0.1.1, 1.0.0, 1.0.1, …
- cpe:2.3:a:robincornett:scriptless_social_sharing:*:*:*:*:*:wordpress:*:*range: <3.2.2
- Range: <3.2.2
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/5b1aacd1-3f75-4a6f-8146-cbb98a713724nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.