Input validation vulnerability in Social Share, Social Login and Social Comments Plugin – Super Socializer 7.13.53

The Super Socializer plugin for WordPress is vulnerable to a type of attack known as Stored Cross-Site Scripting. This attack is possible in versions of the plugin up to and including version 7.13.53. It takes advantage of insufficient security in two shortcodes (TheChamp-Counter and TheChamp-Sharing) which fail to properly check and filter user supplied data. If someone with contributor level access or higher is able to inject malicious code, it will execute on any page the code is injected into whenever a user visits the page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.