What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Complete SEO Page/Post Specific Social Share Buttons pagepost-specific-social-share-buttons allows Stored XSS.This issue affects Page/Post Specific Social Share Buttons: from n/a through <= 2.1.
Explanation of Vulnerability in Simple Terms
02Summary
The Page/Post Specific Social Share Buttons plugin for WordPress contains a cross-site request forgery (CSRF) vulnerability affecting versions 2.1 and earlier. An attacker can craft a malicious link or page that, when visited by a logged-in site administrator, performs unwanted actions on the site without the administrator's knowledge or consent. The vulnerability requires user interaction and can affect the confidentiality, integrity, and availability of the site.
What an attacker can do
03Attacker Capabilities
Trick a site admin into visiting a malicious page to perform unwanted actions on the site without their consent.
Potential impact on your site
04Site Impact
An attacker can modify plugin settings, alter social share button configuration, or perform other admin actions if an admin visits a compromised page.
Conditions required to exploit
05Prerequisites
A logged-in site administrator must visit an attacker-controlled page or click a malicious link.
Key dates
06Disclosure timeline
February 13, 2025
CVE published
April 28, 2026
Record updated