CVE-2025-64198
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Easy Social Share Buttons easy-social-share-buttons3 allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through < 10.7.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in Easy Social Share Buttons plugin through 10.7.1 allows attackers to inject malicious scripts via crafted input.
The Easy Social Share Buttons WordPress plugin contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user input during web page generation. The issue affects versions from n/a through 10.7.1, where the plugin fails to sanitize or escape input before including it in output, enabling script injection [1].
Exploitation
Attackers can exploit this by crafting a malicious link or URL that includes a script payload. User interaction is required — a privileged user (such as an administrator) must click the link, visit a crafted page, or submit a specially designed form. Once triggered, the injected script executes in the context of the victim's browser session, typically within the WordPress admin dashboard or front-end where the vulnerable component renders [1].
Impact
Successful exploitation allows an attacker to inject arbitrary HTML and JavaScript into the affected site. This can be used to redirect visitors to malicious sites, display unwanted advertisements, steal session cookies, or perform other actions that compromise the integrity of the website. The CVSS v3 base score of 7.1 (High) reflects the potential for significant harm, and the vulnerability is expected to become actively exploited in mass campaigns targeting thousands of websites [1].
Mitigation
The vendor has released version 10.7.1 which addresses the vulnerability. Users are strongly advised to update immediately to this patched version. As a workaround, administrators unable to update can consult their hosting provider or web developer for additional security measures. Patchstack has also issued a virtual mitigation rule to block attacks until the update is applied [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <10.7.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.