NextScripts - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nxs_fbembed' Shortcode vulnerability
medium
Authenticated (Contributor+) Stored Cross-Site Scripting via 'nxs_fbembed' Shortcode vulnerability
- CVSS:
- 6.5
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Mar 10, 2026
NextScripts: Social Networks Auto-Poster <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nxs_fbembed' Shortcode
medium
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in all versions up to, and including, 4.4.6. This is due to insufficient input sanitization and output escaping on the `snapFB` post meta value. This makes it possible for aut...
- CVSS:
- 6.4
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Mar 9, 2026
CVE-2026-3228 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] <= 4.4.7 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7.
- Affected:
- up to 4.4.7
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2026
CVE-2026-27379 on NVD →
NextScripts: Social Networks Auto-Poster <= 4.4.7 - Authenticated (Contributor+) PHP Object Injection
high
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.7 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain...
- CVSS:
- 7.5
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.8
- Disclosed:
- Feb 24, 2026
CVE-2026-27379 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.18
unknown
[en] The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform...
- Affected:
- up to 4.3.18
- Fixed in:
- 4.3.18
- Disclosed:
- Oct 16, 2024
CVE-2020-36831 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] <= 4.4.6 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NextScripts allows Reflected XSS.This issue affects NextScripts: from n/a through 4.4.6.
- Affected:
- up to 4.4.6
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2024
CVE-2024-37275 on NVD →
NextScripts <= 4.4.6 - Reflected Cross-Site Scripting
medium
The NextScripts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...
- CVSS:
- 6.1
- Affected:
- up to 4.4.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2024
CVE-2024-37275 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.4.4
unknown
[en] The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing or incorrect nonce validation on the nxssnap-reposter page. This makes it possible for unauthenticated attackers to delete arbitrary post...
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.4
- Disclosed:
- May 22, 2024
CVE-2024-1446 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.4.4
unknown
[en] The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_USER_AGENT header in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitr...
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.4
- Disclosed:
- May 22, 2024
CVE-2024-1762 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.4.4
unknown
[en] The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSettings' function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data includ...
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.4
- Disclosed:
- May 22, 2024
CVE-2024-2088 on NVD →
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Cross-Site Request Forgery to Arbitrary Post Deletion
medium
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing or incorrect nonce validation on the nxssnap-reposter page. This makes it possible for unauthenticated attackers to delete arbitrary posts or...
- CVSS:
- 5.4
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.4
- Disclosed:
- May 21, 2024
CVE-2024-1446 on NVD →
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure
high
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSettings' function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including s...
- CVSS:
- 8.5
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.4
- Disclosed:
- May 21, 2024
CVE-2024-2088 on NVD →
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Unauthenticated Stored Cross-Site Scripting via User Agent
medium
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_USER_AGENT header in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...
- CVSS:
- 6.1
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.4
- Disclosed:
- May 21, 2024
CVE-2024-1762 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.4.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.This issue affects NextScripts: Social Networks Auto-Poster: from n/a through 4.4.2.
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.3
- Disclosed:
- Dec 15, 2023
CVE-2023-49183 on NVD →
NextScripts <= 4.4.2 - Reflected Cross-Site Scripting via code
medium
The NextScripts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘code’ parameter in versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.3
- Disclosed:
- Nov 29, 2023
CVE-2023-49183 on NVD →
NextScripts: Social Networks Auto-Poster <= 4.3.25 - Reflected Cross-Site Scripting
medium
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.3.25. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 6.1
- Affected:
- up to 4.3.25
- Fixed in:
- 4.3.26
- Disclosed:
- Jul 4, 2022
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.26
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress NextScripts: Social Networks Auto-Poster plugin (versions <= 4.3.25).
Update the WordPress NextScripts plugin to the latest available version (at least 4.3.26).
- Affected:
- up to 4.3.26
- Fixed in:
- 4.3.26
- Disclosed:
- Jul 4, 2022
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.26
unknown
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.3.25. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- Affected:
- up to 4.3.26
- Fixed in:
- 4.3.26
- Disclosed:
- Jul 4, 2022
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.25
unknown
[en] The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack
- Affected:
- up to 4.3.25
- Fixed in:
- 4.3.25
- Disclosed:
- Feb 1, 2022
CVE-2021-25072 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.25
unknown
[en] The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue
- Affected:
- up to 4.3.25
- Fixed in:
- 4.3.25
- Disclosed:
- Feb 1, 2022
CVE-2021-24975 on NVD →
NextScripts: Social Networks Auto-Poster <= 4.3.24 - Arbitrary Post Deletion via Cross-Site Request Forgery
medium
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack
- CVSS:
- 6.5
- Affected:
- up to 4.3.25
- Fixed in:
- 4.3.25
- Disclosed:
- Jan 3, 2022
CVE-2021-25072 on NVD →
NextScripts: Social Networks Auto-Poster <= 4.3.23 - Unauthenticated Stored Cross-Site Scripting
medium
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 4.3.24
- Fixed in:
- 4.3.24
- Disclosed:
- Jan 3, 2022
CVE-2021-24975 on NVD →
NextScripts: Social Networks Auto-Poster <= 4.3.20 - Reflected Cross-Site Scripting
medium
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript in...
- CVSS:
- 6.1
- Affected:
- up to 4.3.20
- Fixed in:
- 4.3.21
- Disclosed:
- Nov 28, 2021
CVE-2021-38356 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.25
unknown
[en] The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScri...
- Affected:
- up to 4.3.25
- Fixed in:
- 4.3.25
- Disclosed:
- Nov 1, 2021
CVE-2021-38356 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.18
unknown
Insufficient Privilege Validation vulnerability found by John Castro (Sucuri) in WordPress NextScripts: Social Networks Auto-Poster plugin (versions <= 4.3.17).
- Affected:
- up to 4.3.18
- Fixed in:
- 4.3.18
- Disclosed:
- Sep 6, 2020
NextScripts: Social Networks Auto-Poster <= 4.3.17 - Missing Authorization
medium
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restr...
- CVSS:
- 5
- Affected:
- up to 4.3.17
- Fixed in:
- 4.3.18
- Disclosed:
- Sep 5, 2020
CVE-2020-36831 on NVD →
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.18
unknown
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restr...
- Affected:
- up to 4.3.18
- Fixed in:
- 4.3.18
- Disclosed:
- Sep 5, 2020
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.2.8
unknown
[en] The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS.
- Affected:
- up to 4.2.8
- Fixed in:
- 4.2.8
- Disclosed:
- Mar 21, 2019
CVE-2019-9911 on NVD →
NextScripts: Social Networks Auto-Poster <= 4.2.7 - Reflected Cross-Site Scripting
medium
The NextScripts: Social Networks Auto-Poster plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS.
- CVSS:
- 6.1
- Affected:
- up to 4.2.8
- Fixed in:
- 4.2.8
- Disclosed:
- Feb 5, 2019
CVE-2019-9911 on NVD →
NextScripts: Social Networks Auto-Poster <= 3.4.17 - Stored Cross-Site Scripting
high
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nxsMainFromElementAccts’ parameter in versions before 3.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- CVSS:
- 7.2
- Affected:
- up to 3.4.18
- Fixed in:
- 3.4.18
- Disclosed:
- May 25, 2015
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 3.4.18
unknown
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nxsMainFromElementAccts’ parameter in versions before 3.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- Affected:
- up to 3.4.18
- Fixed in:
- 3.4.18
- Disclosed:
- May 25, 2015
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 3.4.18
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 3.4.18
- Fixed in:
- 3.4.18
- Disclosed:
- May 25, 2015
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 3.4.18
unknown
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to a Persistent XSS attack on the settings screen, due to a lack of sanitation of user input, and lack of Cross-Site Request Forgery token (nonce).
- Affected:
- up to 3.4.18
- Fixed in:
- 3.4.18
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.18
unknown
The plugin is giving access to several functionalities without proper authorisation checks, allowing low privileged attackers the possibility to Remove Posts (by corrupting the post type and other data), Post Arbitrary Information in the site social networks as well as Change the plugin settings.
- Affected:
- up to 4.3.18
- Fixed in:
- 4.3.18
NextScripts: Social Networks Auto-Poster [social-networks-auto-poster-facebook-twitter-g] < 4.3.26
unknown
The plugin does not escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 4.3.26
- Fixed in:
- 4.3.26