Stored Cross-Site Scripting Vulnerability in Social Rocket Plugin by WordPress
CVE-2026-1923
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 April 2026
What is CVE-2026-1923?
The Social Rocket – Social Sharing Plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input validation and output filtering in the 'id' parameter. This flaw enables authenticated attackers with Subscriber-level access or higher to insert arbitrary web scripts which execute when users access the compromised pages, potentially leading to unauthorized access or data manipulation.
Affected Version(s)
Social Rocket – Social Sharing Plugin 0 <= 1.3.4.2