CVE-2021-24656: Wpbrigade Simple Social Buttons
Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected products
- Wpbrigade Simple Social Buttons: before 3.2.4 (fixed in 3.2.4)
Published 2021-10-11. Last modified 2026-06-17.