Stored Cross-Site Scripting Vulnerability in Advanced Social Media Icons Plugin for WordPress
CVE-2026-7659
6.4MEDIUM
What is CVE-2026-7659?
The Advanced Social Media Icons plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the social shortcode. This issue arises from a lack of proper input sanitization and output escaping on attributes provided by users. Authenticated attackers with Contributor-level access or higher can exploit this flaw to inject malicious web scripts into pages, which will execute whenever a user accesses the compromised page. It highlights the importance of rigorous security practices to protect users from potentially harmful scripts.
Affected Version(s)
Advanced Social Media Icons 0 <= 1.2