SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19719

MEDIUM · CVSS 6.8 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Social Media Share Buttons & Social Sharing Icons WordPress plugin prior to version 3.0.1 is vulnerable due to improper escaping of post titles in inline JavaScript event handlers, enabling users with Contributor roles and above to execute Stored Cross-Site Scripting (XSS) attacks. This vulnerability can be exploited when a visitor interacts with the affected buttons, particularly if a non-default icon display configuration is in use. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19719
Severity
MEDIUM
CVSS
6.8
EPSS
0.29%
WordPress Java

Original NVD Description

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.