Reflected Cross-Site Scripting Vulnerability in Social Media Share Buttons & Social Sharing Icons Plugin
CVE-2026-19723

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-19723?

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress, prior to version 3.0.1, contains a security flaw where it fails to properly escape user input. This weakness allows attackers to execute reflected cross-site scripting (XSS) attacks by injecting malicious scripts via an inline JavaScript event handler. The vulnerability is triggered when users interact with affected buttons, specifically in scenarios where the plugin is operating under a non-default icon display configuration.

Affected Version(s)

Social Media Share Buttons & Social Sharing Icons 0 < 3.0.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mohammed Abd Alrahman
WPScan
.