CVE-2016-10736: Devpups Social Pug
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.
Affected products
- Devpups Social Pug: before 1.2.6 (fixed in 1.2.6)
Published 2019-01-09. Last modified 2026-06-17.