Hubbub Lite <= 1.36.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Hubbub Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.36.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 1.36.3
- Fixed in:
- 1.36.3.1
- Disclosed:
- Jul 22, 2026
CVE-2026-27403 on NVD →
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.36.1
unknown
[en] The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dpsp_list_attention_search' parameter in all versions up to, and including, 1.36.0 due to insufficient input sanitization and output escaping. This makes it possible for unau...
- Affected:
- up to 1.36.1
- Fixed in:
- 1.36.1
- Disclosed:
- Nov 6, 2025
CVE-2025-12471 on NVD →
Hubbub Lite <= 1.36.0 - Reflected Cross-Site Scripting
medium
The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dpsp_list_attention_search' parameter in all versions up to, and including, 1.36.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...
- CVSS:
- 6.1
- Affected:
- up to 1.36.0
- Fixed in:
- 1.36.1
- Disclosed:
- Nov 5, 2025
CVE-2025-12471 on NVD →
Hubbub Lite <= 1.35.1 - Authenticated (Subscriber+) Sensitive Information Exposure
medium
The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 1.35.1
- Fixed in:
- 1.36.0
- Disclosed:
- Sep 22, 2025
CVE-2025-58007 on NVD →
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.34.4
unknown
[en] The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.34.4
- Fixed in:
- 1.34.4
- Disclosed:
- May 15, 2025
CVE-2024-10145 on NVD →
Hubbub Lite <= 1.34.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev...
- CVSS:
- 4.4
- Affected:
- up to 1.34.3
- Fixed in:
- 1.34.4
- Disclosed:
- Mar 2, 2025
CVE-2024-10145 on NVD →
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.30.1
unknown
[en] Missing Authorization vulnerability in NerdPress Social Pug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Pug: from n/a through 1.30.0.
- Affected:
- up to 1.30.1
- Fixed in:
- 1.30.1
- Disclosed:
- Dec 9, 2024
CVE-2023-49193 on NVD →
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.33.2
unknown
[en] The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for authenticated attackers, with contributor acce...
- Affected:
- up to 1.33.2
- Fixed in:
- 1.33.2
- Disclosed:
- Apr 9, 2024
CVE-2024-2501 on NVD →
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.33.1
unknown
[en] The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.
- Affected:
- up to 1.33.1
- Fixed in:
- 1.33.1
- Disclosed:
- Apr 1, 2024
CVE-2024-1526 on NVD →
Hubbub Lite – Fast, Reliable Social Network Sharing Buttons <= 1.33.1 - PHP Object Injection
high
The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for authenticated attackers, with contributor access an...
- CVSS:
- 7.5
- Affected:
- up to 1.33.1
- Fixed in:
- 1.33.2
- Disclosed:
- Mar 27, 2024
CVE-2024-2501 on NVD →
Hubbub Lite <= 1.31.0 - Unauthenticated Information Exposure
medium
The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.33.0 via opengraph tags. This makes it possible for unauthenticated attackers to view short excerpts of password protected posts.
- CVSS:
- 5.3
- Affected:
- up to 1.33.0
- Fixed in:
- 1.33.1
- Disclosed:
- Mar 11, 2024
CVE-2024-1526 on NVD →
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.32.0
unknown
[en] The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.32.0
- Fixed in:
- 1.32.0
- Disclosed:
- Jan 16, 2024
CVE-2023-7154 on NVD →
Hubbub Lite <= 1.31.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Hubbub Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.31.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbi...
- CVSS:
- 4.4
- Affected:
- up to 1.31.1
- Fixed in:
- 1.32.0
- Disclosed:
- Jan 11, 2024
CVE-2023-7154 on NVD →
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.2.6
unknown
Update the plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Social Pug Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit...
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Dec 9, 2023
Social Pug <= 1.30.0 - Missing Authorization via multiple admin_init actions
medium
The Social Pug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple functions that run on admin_init in versions up to, and including, 1.20.3. This makes it possible for unauthenticated attackers to dismiss admin notifications and update the database.
- CVSS:
- 5.3
- Affected:
- up to 1.30.0
- Fixed in:
- 1.30.1
- Disclosed:
- Dec 1, 2023
CVE-2023-49193 on NVD →
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.19.0
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Grow Social plugin (versions <= 1.18.2).
Update the WordPress Grow Social plugin to the latest available version (at least 1.19.0).
- Affected:
- up to 1.19.0
- Fixed in:
- 1.19.0
- Disclosed:
- Jun 13, 2022
Grow Social <= 1.18.2 - Reflected Cross-Site Scripting
medium
The Grow Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.18.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...
- CVSS:
- 6.1
- Affected:
- up to 1.18.2
- Fixed in:
- 1.19.0
- Disclosed:
- Jul 8, 2021
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.19.0
unknown
The Grow Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.18.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...
- Affected:
- up to 1.19.0
- Fixed in:
- 1.19.0
- Disclosed:
- Jul 8, 2021
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.2.6
unknown
[en] The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jan 9, 2019
CVE-2016-10736 on NVD →
Grow Social <= 1.2.5 - Reflected Cross-Site Scripting
medium
The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.6
- Disclosed:
- Dec 9, 2016
CVE-2016-10736 on NVD →
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.2.6
unknown
This plugin is prone to a cross site scripting vulnerability. It allows attackers to inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Dec 9, 2016
Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.19.0
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 1.19.0
- Fixed in:
- 1.19.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database