Executive brief
The Social Media & Share Icons WordPress plugin allows attackers to inject malicious scripts into website pages without authentication. Successful exploitation can steal visitor data, hijack user accounts, or redirect site traffic to malicious destinations. Affected websites must update to version 3.0.0 or later immediately to block ongoing attacks.
Technical details
This is an unauthenticated reflected or stored cross-site scripting (XSS) vulnerability in WordPress Social Media & Share Icons plugin versions up to 2.9.9. The vulnerability is caused by insufficient input validation or output encoding in the plugin's handling of user-supplied data. An attacker can inject arbitrary JavaScript code that executes in the context of a visitor's browser, leading to session hijacking, credential theft, or malware distribution. While the vulnerability requires user interaction (visiting a crafted link or page), the lack of authentication requirement makes it widely exploitable in mass-attack campaigns. Patched in version 3.0.0 and later.
Affected products
- WordPress Social Media & Share Icons <=2.9.9
Timeline
- 2026-08-20: disclosed: Vulnerability reported by Bonds on 2026-06-15, published on 2026-08-20
- 2026-08-20: patched: Patched in version 3.0.0