CISA KEV 정보
| 취약점명 | WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability |
|---|---|
| 설명 | WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-79 |
| 등록일 (KEV) | 2021-11-03 |
| 조치 기한 | 2022-05-03 |
| 추가 참고 | https://nvd.nist.gov/vuln/detail/CVE-2019-9978 |
NVD 상세 정보
CVSS v3.1: 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCVSS v2.0: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N설명: The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
CWE: CWE-79 | CWE-79
참조
- http://packetstormsecurity.com/files/152722/Wordpress-Social-Warfare-Remote-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/163680/WordPress-Social-Warfare-3.5.2-Remote-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- https://blog.sucuri.net/2019/03/zero-day-stored-xss-in-social-warfare.html [Exploit, Third Party Advisory]
- https://twitter.com/warfareplugins/status/1108852747099652099 [Third Party Advisory]
- https://wordpress.org/plugins/social-warfare/#developers [Product]
- https://wpvulndb.com/vulnerabilities/9238 [Broken Link, Third Party Advisory]
- https://www.cybersecurity-help.cz/vdb/SB2019032105 [Exploit, Third Party Advisory]
- https://www.exploit-db.com/exploits/46794/ [Third Party Advisory, VDB Entry]
- https://www.pluginvulnerabilities.com/2019/03/21/full-disclosure-of-settings-change-persistent-cross-site-scripting-xss-vulnerability-in-social-warfare/ [Exploit, Third Party Advisory]
- https://www.wordfence.com/blog/2019/03/unpatched-zero-day-vulnerability-in-social-warfare-plugin-exploited-in-the-wild/ [Third Party Advisory]
- http://packetstormsecurity.com/files/152722/Wordpress-Social-Warfare-Remote-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/163680/WordPress-Social-Warfare-3.5.2-Remote-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- http://seclists.org/fulldisclosure/2025/Jun/1 [Mailing List]
- https://blog.sucuri.net/2019/03/zero-day-stored-xss-in-social-warfare.html [Exploit, Third Party Advisory]
- https://twitter.com/warfareplugins/status/1108852747099652099 [Third Party Advisory]
- ... 외 7건
This product uses the NVD API but is not endorsed or certified by the NVD.