Cross-site Scripting Vulnerability in WP Social Widget by Catchsquare
CVE-2025-49306

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

What is CVE-2025-49306?

The WP Social Widget developed by Catchsquare is affected by a vulnerability that allows attackers to exploit improper neutralization of input during web page generation. This results in stored cross-site scripting (XSS), potentially compromising user interactions. This security flaw impacts versions of the WP Social Widget from its inception through version 2.3, enabling unauthorized scripts to be executed within the context of a victim's browser. As a result, sensitive information could be harvested, and users could be misled into performing unintended actions.

Affected Version(s)

WP Social Widget <= 2.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

muhammad yudha (Patchstack Alliance)
.