CVE-2019-9978
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- March 24, 2019
- Published Date
- March 24, 2019
- Last Updated
- February 07, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
CVSS Scores
SSVC Information
- Exploitation
- active
- Technical Impact
- partial
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9978.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
echoosso/CVE-2019-9978
Type: github • Created: 2025-03-27 23:18:51 UTC • Stars: 1
MAHajian/CVE-2019-9978
Type: github • Created: 2024-09-20 11:25:45 UTC • Stars: 0
grimlockx/CVE-2019-9978
Type: github • Created: 2023-01-20 16:29:18 UTC • Stars: 3
d3fudd/CVE-2019-9978_Exploit
Type: github • Created: 2022-11-15 01:22:38 UTC • Stars: 2
KTN1990/CVE-2019-9978
Type: github • Created: 2019-05-06 04:48:43 UTC • Stars: 6
hash3liZer/CVE-2019-9978
Type: github • Created: 2019-05-03 05:57:44 UTC • Stars: 19
mpgn/CVE-2019-9978
Type: github • Created: 2019-03-25 23:38:58 UTC • Stars: 8