Executive brief
The Shariff Wrapper plugin for WordPress, which provides privacy-compliant social media share buttons, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. These scripts execute automatically when other users visit the affected page, potentially leading to unauthorized actions or data theft. This could damage a site's reputation or be used to redirect visitors to malicious websites.
Technical details
The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'headline' parameter within the [shariff] shortcode. The vulnerability stems from the use of a custom wp_kses implementation with overly permissive HTML tags, followed by a str_replace operation that injects HTML after the sanitization phase. This allows authenticated attackers with Contributor-level permissions or higher to introduce malicious event handlers through the %total placeholder in the style attribute. When a user views the compromised page, the injected script executes in their browser context. The issue is addressed in version 4.6.21.
Affected products
- Shariff Wrapper Team Shariff Wrapper Up to and including 4.6.20
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory
References
- https://plugins.trac.wordpress.org/browser/shariff/trunk/shariff.php
- https://plugins.trac.wordpress.org/browser/shariff/trunk/shariff.php
- https://plugins.trac.wordpress.org/browser/shariff/trunk/shariff.php
- https://plugins.trac.wordpress.org/browser/shariff/trunk/shariff.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3532532%40shariff&new=3532532%40shariff&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e037d22a-3d4d-4f70-a749-6d6c552c7553?source=cve