CISA Known Exploited Vulnerability

CVE-2019-9978

WordPress · Social Warfare Plugin

WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

Date added
BOD 22-01 due date
CWE CWE-79
Ransomware Unknown

CISA description

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

Required action

Apply updates per vendor instructions.