plugin

Social Warfare Vulnerabilities

24 known security issues reported for the Social Warfare WordPress plugin. Most recent disclosed Feb 22, 2025.

2 critical 1 high 6 medium

Running Social Warfare on your site? Check whether your installed version is affected.

Scan your site free

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 4.5.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WarfarePlugins Social Warfare allows DOM-Based XSS. This issue affects Social Warfare: from n/a through 4.5.4.

Affected:
up to 4.5.6
Fixed in:
4.5.6
Disclosed:
Feb 22, 2025

CVE-2025-26973 on NVD →

Social Sharing Plugin – Social Warfare <= 4.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbi...

CVSS:
6.4
Affected:
up to 4.5.5
Fixed in:
4.5.6
Disclosed:
Feb 19, 2025

CVE-2025-26973 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 4.4.7.3

unknown

<p>WordPress Social Warfare Plugin <= 4.4.7.1 is vulnerable to Backdoor</p><p>Affected Version <= 4.4.7.1</p><p>Fixed in version 4.4.7.3 </p>

Affected:
up to 4.4.7.3
Fixed in:
4.4.7.3
Disclosed:
Jul 3, 2024

Social Sharing Plugin &#8211; Social Warfare [social-warfare] >= 4.4.6.4 - <= 4.4.7.1

unknown

[en] Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send tha...

Affected:
4.4.6.4 – 4.4.7.1
Fixed in:
4.4.7.1
Disclosed:
Jun 25, 2024

CVE-2024-6297 on NVD →

Several WordPress.org Plugins <= Various Versions - Injected Backdoor

critical

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...

CVSS:
10
Affected:
4.4.6.4 – 4.4.7.1
Fixed in:
4.4.7.3
Disclosed:
Jun 24, 2024

CVE-2024-6297 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] >= 4.4.6.4 - <= 4.4.7.1

unknown

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...

Affected:
4.4.6.4 – 4.4.7.1
Fixed in:
4.4.7.1
Disclosed:
Jun 24, 2024

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 4.4.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: from n/a through 4.4.5.1.

Affected:
up to 4.4.6
Fixed in:
4.4.6
Disclosed:
May 10, 2024

CVE-2024-34825 on NVD →

Social Sharing Plugin – Social Warfare <= 4.4.5.1 - Cross-Site Request Forgery

medium

The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.5.1. This is due to missing or incorrect nonce validation on the options_page_scan_url() function. This makes it possible for unauthenticated attackers to trigger a scan...

CVSS:
4.3
Affected:
up to 4.4.5.1
Fixed in:
4.4.6
Disclosed:
May 9, 2024

CVE-2024-34825 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 4.4.6.2

unknown

[en] The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialWarfare' shortcode in all versions up to, and including, 4.4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

Affected:
up to 4.4.6.2
Fixed in:
4.4.6.2
Disclosed:
May 2, 2024

CVE-2024-1959 on NVD →

Social Sharing Plugin – Social Warfare <= 4.4.6.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialWarfare' shortcode in all versions up to, and including, 4.4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

CVSS:
6.4
Affected:
up to 4.4.6.1
Fixed in:
4.4.6.2
Disclosed:
Apr 22, 2024

CVE-2024-1959 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 3.5.3

unknown

[en] The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Jan 17, 2024

CVE-2021-4434 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 4.4.4

unknown

[en] The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...

Affected:
up to 4.4.4
Fixed in:
4.4.4
Disclosed:
Nov 7, 2023

CVE-2023-4842 on NVD →

Social Sharing Plugin - Social Warfare <= 4.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers w...

CVSS:
6.4
Affected:
up to 4.4.3
Fixed in:
4.4.4
Disclosed:
Nov 6, 2023

CVE-2023-4842 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 4.4.0

unknown

[en] The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.0. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it possible for unauthenticated attackers to delete post meta information and reset network access to...

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Jan 19, 2023

CVE-2023-0403 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 4.4.0

unknown

[en] The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset...

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Jan 19, 2023

CVE-2023-0402 on NVD →

Social Warfare <= 4.3.1 - Cross-Site Request Forgery

medium

The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it possible for unauthenticated attackers to delete post meta information and reset network access tokens,...

CVSS:
5.4
Affected:
up to 4.3.1
Fixed in:
4.4.0
Disclosed:
Jan 5, 2023

CVE-2023-0403 on NVD →

Social Warfare <= 4.3.0 - Missing Authorization

medium

The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete post meta information and reset netw...

CVSS:
5.4
Affected:
up to 4.3.0
Fixed in:
4.3.1
Disclosed:
Jan 5, 2023

CVE-2023-0402 on NVD →

Social Warfare <= 3.5.2 - Remote Code Execution

critical

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.

CVSS:
10
Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Apr 29, 2021

CVE-2021-4434 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 3.5.3

unknown

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Apr 29, 2021

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 3.5.3

unknown

Unauthenticated Remote Code Execution (RCE) vulnerability found by Luka Sikic in WordPress Social Warfare plugin (versions <= 3.5.2).

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Apr 24, 2019

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 3.5.3

unknown

[en] The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Mar 24, 2019

CVE-2019-9978 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 3.5.3

unknown

Unauthenticated Arbitrary Settings Update vulnerability found in WordPress Social Warfare plugin (versions <= 3.5.2).

Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Mar 22, 2019

Social Warfare <= 3.5.2 - Unauthenticated Arbitrary Settings Update

high

The Social Warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

CVSS:
7.2
Affected:
up to 3.5.3
Fixed in:
3.5.3
Disclosed:
Mar 21, 2019

CVE-2019-9978 on NVD →

Social Sharing Plugin &#8211; Social Warfare [social-warfare] < 3.5.3

unknown

Unauthenticated remote code execution has been discovered in functionality that handles settings import.

Affected:
up to 3.5.3
Fixed in:
3.5.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database