| Added |
CPE Configuration |
|
OR
*cpe:2.3:a:warfareplugins:social_warfare:*:*:*:*:*:wordpress:*:* versions up to (excluding) 3.5.3
*cpe:2.3:a:warfareplugins:social_warfare_pro:*:*:*:*:*:wordpress:*:* versions up to (excluding) 3.5.3 |
| Added |
CVSS V2 |
|
(AV:N/AC:M/Au:N/C:N/I:P/A:N) |
| Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism |
| Added |
CVSS V3 |
|
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| Added |
CWE |
|
CWE-79 |
| Changed |
Reference Type |
https://blog.sucuri.net/2019/03/zero-day-stored-xss-in-social-warfare.html No Types Assigned |
https://blog.sucuri.net/2019/03/zero-day-stored-xss-in-social-warfare.html Exploit, Third Party Advisory |
| Changed |
Reference Type |
https://twitter.com/warfareplugins/status/1108852747099652099 No Types Assigned |
https://twitter.com/warfareplugins/status/1108852747099652099 Third Party Advisory |
| Changed |
Reference Type |
https://wordpress.org/plugins/social-warfare/#developers No Types Assigned |
https://wordpress.org/plugins/social-warfare/#developers Product, Third Party Advisory |
| Changed |
Reference Type |
https://wpvulndb.com/vulnerabilities/9238 No Types Assigned |
https://wpvulndb.com/vulnerabilities/9238 Third Party Advisory |
| Changed |
Reference Type |
https://www.cybersecurity-help.cz/vdb/SB2019032105 No Types Assigned |
https://www.cybersecurity-help.cz/vdb/SB2019032105 Exploit, Third Party Advisory |
| Changed |
Reference Type |
https://www.pluginvulnerabilities.com/2019/03/21/full-disclosure-of-settings-change-persistent-cross-site-scripting-xss-vulnerability-in-social-warfare/ No Types Assigned |
https://www.pluginvulnerabilities.com/2019/03/21/full-disclosure-of-settings-change-persistent-cross-site-scripting-xss-vulnerability-in-social-warfare/ Exploit, Third Party Advisory |
| Changed |
Reference Type |
https://www.wordfence.com/blog/2019/03/unpatched-zero-day-vulnerability-in-social-warfare-plugin-exploited-in-the-wild/ No Types Assigned |
https://www.wordfence.com/blog/2019/03/unpatched-zero-day-vulnerability-in-social-warfare-plugin-exploited-in-the-wild/ Third Party Advisory |