VYPR
Medium severity5.9NVD Advisory· Published Apr 26, 2024· Updated Apr 28, 2026

CVE-2024-33693

CVE-2024-33693

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meks Meks Smart Social Widget allows Stored XSS.This issue affects Meks Smart Social Widget: from n/a through 1.6.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Meks Smart Social Widget plugin allows attackers to inject malicious scripts via widget settings, affecting versions up to 1.6.4.

The Meks Smart Social Widget plugin for WordPress suffers from a stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. This issue affects plugin versions from n/a through 1.6.4. The vulnerability allows attackers to inject arbitrary scripts that are stored in the widget's settings.

To exploit this vulnerability, an attacker must have authenticated access to the WordPress admin panel with the ability to modify widget settings (e.g., an administrator role). Upon injection, the malicious script is stored and executed when other users, including site visitors, load pages containing the widget [1]. User interaction is not required from the victim; the script executes automatically.

Successful exploitation could allow an attacker to perform actions such as redirecting visitors to malicious sites, displaying advertisements, stealing cookies, or defacing the website [1]. This vulnerability is classified with a CVSS v3 score of 5.9 (Medium) and is known to be used in mass-exploit campaigns against thousands of websites.

The vulnerability has been patched in version 1.6.5 of the plugin. Users are strongly advised to update to this version or enable automatic updates for vulnerable plugins [1]. If immediate update is not possible, restricting access to plugin settings or consulting a web developer is recommended.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.