Home

Description

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputting them in a dashboard, which could allow users with the contributor role to perform Cross-Site Scripting attacks.

PUBLISHED Reserved 2025-04-30 | Published 2025-05-22 | Updated 2025-05-22 | Assigner WPScan

Problem types

CWE-79 Cross-Site Scripting (XSS)

Product status

Default status
unaffected

Any version before 8.4.0
affected

Credits

Krugov Artyom finder

WPScan coordinator

References

wpscan.com/...rability/ebd7e5f5-af8d-42ca-b6ff-af92e03d4a3e/ exploit vdb-entry technical-description

cve.org (CVE-2025-4133)

nvd.nist.gov (CVE-2025-4133)

Download JSON