CVE-2016-10736: Devpups Social Pug

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.

Affected products

  • Devpups Social Pug: before 1.2.6 (fixed in 1.2.6)

Published 2019-01-09. Last modified 2026-06-17.