S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2019-9978 Scanner

CVE-2019-9978 scanner - Remote Code Execution (RCE) vulnerability in Social Warfare plugin for WordPress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-9978
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Social Warfare plugin for WordPress is a popular social media sharing and optimization plugin used by website owners, bloggers, and digital marketers. It is designed to help increase website traffic by making it easy for visitors to share content on social media platforms such as Facebook, Twitter, Pinterest, and LinkedIn. With over 70,000 active installations, the Social Warfare plugin is one of the most widely used social sharing plugins in WordPress.

Recently, a critical vulnerability code was detected in the Social Warfare plugin, specifically CVE-2019-9978. This vulnerability allowed hackers to exploit the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, exposing the website to stored cross-site scripting (XSS) attacks. Hackers could inject malicious code into the website, and when users visited or interacted with the affected page, their sensitive data could be stolen or manipulated without their knowledge.

The potential consequences of this vulnerability being exploited are severe. Hackers could steal sensitive data such as login credentials, personal information, and financial details. They could even manipulate the website by inserting malicious code that could redirect visitors to phishing sites or malware-infected pages.

Finally, it's important to note that security is an ongoing process and not a one-time task. Regularly updating software, monitoring for vulnerabilities, and ensuring that website security systems are up to date is crucial to keeping your website safe from attacks. With the help of pro features offered by s4e.io platform, website owners can easily and quickly identify vulnerabilities in their digital assets, protecting their websites, and their visitors, from any potential threats. Don't wait until it's too late – start taking action today to ensure your website's security.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are a few precautions that can be taken. Here are some best practices:

  • Update to the latest version of the Social Warfare plugin (version 3.5.3 or later),which addressed this vulnerability.
  • Use a web application firewall (WAF) to block any attempts to exploit the vulnerability.
  • Regularly scan your website for vulnerabilities, using a tool like securityforeveryone.com platform, which offers pro features for quick and easy identification of vulnerabilities in websites.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.