CVE-2026-19723 PUBLISHED

Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Reflected XSS via Pin It Share Handler

Assigner: WPScan
Reserved: 13.08.2026 Published: 02.09.2026 Updated: 02.09.2026

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.

Product Status

Vendor Unknown
Product Social Media Share Buttons & Social Sharing Icons
Versions Default: unaffected
  • affected from 0 to 3.0.1 (excl.)

Credits

  • Mohammed Abd Alrahman finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE