Reflected Cross-Site Scripting Vulnerability in NextScripts Social Networks Auto-Poster WordPress Plugin
CVE-2026-16570
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 August 2026
Badges
What is CVE-2026-16570?
The NextScripts Social Networks Auto-Poster WordPress plugin prior to version 4.4.8 is susceptible to reflected Cross-Site Scripting (XSS) due to improper escaping of certain query-string parameters. This vulnerability can be exploited by malicious actors to craft special links that, when clicked by logged-in users, including administrators, can lead to arbitrary script execution in the context of the user's session. This poses a significant security risk as it may allow attackers to steal sensitive information, hijack user sessions, or perform other harmful actions.
Affected Version(s)
NextScripts: Social Networks Auto-Poster 0 < 4.4.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.