Junglewise Threat Intelligence

CVE-2019-9978: WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

CVE-2019-9978 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2021-11-03

Vendors: Wordpress.

Executive brief

The Social Warfare and Social Warfare Pro plugins for WordPress are vulnerable to stored Cross-Site Scripting (XSS) via the swp_url parameter in wp-admin/admin-post.php?swp_debug=load_options. This vulnerability can be leveraged to achieve remote code execution and was exploited in the wild as a zero-day.

Affected products

  • Social Warfare Social Warfare before 3.5.3
  • Social Warfare Social Warfare Pro before 3.5.3

Timeline

  • 2019-03-21: disclosed: Zero-day vulnerability reported and exploited in the wild.
  • 2019-03-21: exploited: Exploitation in the wild observed in March 2019.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.