Reflected Cross-Site Scripting Vulnerability in NextScripts Social Networks Auto-Poster WordPress Plugin
CVE-2026-16570

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-16570?

The NextScripts Social Networks Auto-Poster WordPress plugin prior to version 4.4.8 is susceptible to reflected Cross-Site Scripting (XSS) due to improper escaping of certain query-string parameters. This vulnerability can be exploited by malicious actors to craft special links that, when clicked by logged-in users, including administrators, can lead to arbitrary script execution in the context of the user's session. This poses a significant security risk as it may allow attackers to steal sensitive information, hijack user sessions, or perform other harmful actions.

Affected Version(s)

NextScripts: Social Networks Auto-Poster 0 < 4.4.8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
WPScan
.