Executive brief
Facebook for WordPress is a popular WordPress plugin that integrates Facebook functionality into websites. An unauthenticated attacker can inject malicious JavaScript code into the site, allowing them to steal visitor data, hijack user accounts, or redirect users to malicious sites. This vulnerability affects all installations running version 5.2.1 and earlier.
Technical details
The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in Facebook for WordPress plugin versions 5.2.1 and earlier. The plugin fails to properly sanitize or validate user input before rendering it in the web interface, allowing attackers to inject arbitrary JavaScript. The attack requires no authentication and can be exploited via a crafted link or form submission; user interaction (such as clicking a link) may be required depending on the attack vector. Successful exploitation allows attackers to execute arbitrary JavaScript in the context of an affected website, potentially leading to data theft, account hijacking, or malware distribution. A patch is available in version 5.2.2 and later.
Affected products
- Facebook Facebook for WordPress <= 5.2.1
Timeline
- 2026-07-31: disclosed
- 2026-07-31: patched: Version 5.2.2 and later