CVE-2019-9978 Details
Description
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
A stored cross-site scripting vulnerability has been identified in the WordPress Social Warfare plugin, affecting versions prior to 3.5.3. The issue arises in the wp-admin/admin-post.php file, where the swp_url parameter is not properly sanitized. This flaw allows attackers to inject malicious JavaScript that is executed in the context of the user visiting the site, potentially leading to remote code execution.
Users are advised to update the Social Warfare plugin to version 3.5.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability | Nov 3, 2021 | May 3, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| warfareplugins social warfare | < 3.5.3 |
CPE
Remediation
| |
| warfareplugins social warfare pro | < 3.5.3 |
CPE
Remediation
| |
Change History
19 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 7, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Jun 3, 2025 | Modified Analysis | [email protected] |
| Jun 3, 2025 | CVE Modified | CVE |
| Feb 28, 2025 | Modified Analysis | [email protected] |
| Feb 7, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 25, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 30, 2021 | CVE Modified | [email protected] |
| May 7, 2019 | Modified Analysis | [email protected] |
| May 4, 2019 | CVE Modified | [email protected] |
| May 3, 2019 | CVE Modified | [email protected] |
| Mar 26, 2019 | Initial Analysis | [email protected] |
| Mar 26, 2019 | CVE Modified | [email protected] |