Unauthenticated Cross Site Scripting Vulnerability in Ultimate Social Media Icons Plugin
CVE-2026-66623
7.1HIGH
What is CVE-2026-66623?
The Ultimate Social Media Icons Plugin for WordPress versions up to 2.9.9 is vulnerable to an unauthenticated Cross-Site Scripting (XSS) attack. This vulnerability allows attackers to inject malicious scripts into web pages viewed by unsuspecting users, compromising user security and potentially allowing further exploitation of the website. It is crucial for users and administrators to apply the necessary updates to mitigate this vulnerability.
Affected Version(s)
Social Media & Share Icons <= 2.9.9