Back to search
CVE-2019-9978
Published: Mar 24, 2019
Modified: Oct 21, 2025
PUBLISHED
Description
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://wpvulndb.com/vulnerabilities/9238
x_refsource_MISC
https://www.cybersecurity-help.cz/vdb/SB2019032105
x_refsource_MISC
https://wordpress.org/plugins/social-warfare/#developers
x_refsource_MISC
https://twitter.com/warfareplugins/status/1108852747099652099
x_refsource_MISC
46794
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now