CVE-2019-9978: WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
Medium severity, CVSS 6.1. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 72.9% chance of exploitation in the next 30 days.
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
Affected products
- Warfareplugins Social Warfare: before 3.5.3 (fixed in 3.5.3)
- Warfareplugins Social Warfare Pro: before 3.5.3 (fixed in 3.5.3)
Published 2019-03-24. Last modified 2026-06-17.