S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 14, 2024

CVE-2017-18500 Scanner

CVE-2017-18500 scanner - Cross-Site Scripting (XSS) vulnerability in Social Buttons Pack plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18500
6.1
CVSS

The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Social Buttons Pack plugin for WordPress is a commonly used social media sharing tool that allows the inclusion of social media buttons on websites. With over 10,000 active installations, it is an easy-to-use plugin that enables website owners to share their content on various social media platforms using well-designed social buttons.

However, the plugin was found to have multiple XSS issues, including a vulnerability CVE-2017-18500 that could cause serious harm to the websites using it. The CVE-2017-18500 vulnerability is a stored XSS vulnerability in the social media share counter feature, which can be exploited by attackers to inject and execute malicious scripts in the website's backend.

When exploited, this vulnerability can lead to the hijacking of website sessions by attackers who can access sensitive and confidential information such as user names, emails, and passwords. The attackers can also compromise the website's functionalities, inject malware into the system, and even deface the website. As a result, compromised websites can lose their credibility and trust among their users.

On the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets using the pro features available. With regular scanning and monitoring of websites, s4e.io provides real-time alerts on any detected vulnerabilities and recommended actions to be taken to mitigate the risks. This service provides website owners with the peace of mind they need to know their digital assets are secure from any potential threats and attacks. In conclusion, website owners should prioritize protecting their digital assets by taking necessary precautions and utilizing platforms like s4e.io.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take several precautions, including:

  • Updating the plugin to the latest version available
  • Disabling the share counter feature until a patch is available
  • Implementing input validation and sanitization in website user input fields
  • Employing web application firewalls and security plugins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-18500 scanner - Cross-Site Scripting (XSS) vulnerability in Social Buttons Pack plugin for WordPress | S4E