Sceawere

Vulnerability Detail

CVE-2026-42418UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in Social Rocket

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
socialrocket
Product
Social Rocket
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Social Rocket <= 1.3.5 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:54.900Z",
  "pubdate": "2026-10-06T09:17:54.900Z",
  "executiveSummary": "The Social Rocket plugin for WordPress, in versions 1.3.5 and below, contains a critical security vulnerability involving Unauthenticated Cross-Site Scripting (XSS).\nThis vulnerability allows unauthenticated remote attackers to inject and execute arbitrary JavaScript code within the context of a victim's browser session.\nThe security flaw stems from insufficient sanitization of user-supplied inputs, which are processed and rendered back to the user without adequate output encoding.\nSuccessful exploitation poses a significant risk to the integrity and confidentiality of the affected WordPress environment.\nAn attacker can leverage this vulnerability to hijack administrative sessions, redirect users to malicious sites, perform unauthorized actions on behalf of the victim, or exfiltrate sensitive cookies and session tokens.\nAs the attack requires no prior authentication, it is accessible to any remote threat actor capable of crafting a malicious HTTP request directed at the target application.\nThe vulnerability represents a severe threat to site visitors and administrators, as the exploit is triggered passively when an authenticated user views the injected content.",
  "technicalDetails": "The vulnerability is a reflected or stored Cross-Site Scripting (XSS) flaw located within the Social Rocket plugin's handling of input parameters. The root cause is the failure of the application to properly sanitize or validate input data before echoing it into the HTML document, effectively allowing the injection of arbitrary HTML tags and client-side scripts.\nBecause the plugin does not enforce proper output encoding mechanisms, specifically within the fields responsible for rendering social media sharing configurations or dynamic content elements, an attacker can supply malicious payloads containing scripts (e.g., <script>alert(document.cookie)</script>) in parameters that the application reflects back to the browser.\nThe attack flow proceeds as follows: First, the attacker identifies a vulnerable parameter within the Social Rocket plugin that is reflected on a public-facing page or an administrative dashboard. Second, the attacker crafts a malicious request—potentially delivered via a phishing link or by directly manipulating input forms—that includes the JavaScript payload. Third, when a victim, such as a site administrator or a regular user, visits the page where the payload has been rendered, the browser interprets the script as legitimate source code and executes it within the victim's session.\nThis execution happens entirely client-side, meaning the attacker gains the ability to execute any command within the Document Object Model (DOM) of the victim's browser. The implications are severe: the script can access document.cookie to steal session identifiers, bypass Same-Origin Policy (SOP) limitations in specific contexts, or modify the visible content of the page to conduct credential harvesting or drive-by downloads.\nGiven that the vulnerability does not require authentication, it is highly accessible via standard HTTP/HTTPS channels. There are no privilege requirements, as the malicious script runs with the permissions of the victim currently accessing the affected page. Post-exploitation impact is limited only by the privileges of the victim; if an administrator views the page, the attacker can effectively take control of the entire WordPress instance by performing administrative actions, such as creating new users or modifying system settings."
}
CVE-2026-42418: Unauthenticated XSS in Social Rocket (HIGH Severity, CVSS: 7.1) | Sceawere