LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-9978: WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-9978 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

CVE-2019-9978 is a cross-site scripting (XSS) vulnerability in the WordPress Social Warfare plugin (including Social Warfare Pro). According to CISA, the flaw can allow remote code execution. It matters because a successful exploit can let an attacker run script in the context of a site administrator or other user, potentially leading to full site compromise on WordPress installations that use the plugin.

Defenders should treat this as a high-priority plugin issue: inventory WordPress sites for the Social Warfare family of plugins, confirm whether they are still present and unpatched, and apply the vendor’s updates without delay. Specifics such as exact affected versions must be confirmed against the vendor advisory.

How it works

The weakness is CWE-79 (Improper Neutralization of Input During Web Page Generation), commonly called cross-site scripting. In this class of flaw, untrusted input is reflected or stored and later rendered in a page without proper output encoding or sanitization. An attacker who can supply that input can inject script that executes in the browser of a victim who views the crafted content.

CISA notes that this particular XSS in Social Warfare and Social Warfare Pro can lead to remote code execution. In a typical WordPress plugin XSS-to-RCE path, the injected script runs with the privileges of an authenticated administrator (for example via a malicious link or stored payload), allowing the attacker to create a new admin user, install a malicious plugin or theme, or drop a web shell. Exact request parameters, endpoints, or payload formats are not provided here; treat any public proof-of-concept material cautiously and validate behavior only in a controlled lab against the vendor’s description.

Am I affected? How to find it in your systems

Social Warfare is a WordPress plugin used to add social sharing buttons and related features. It commonly appears on public-facing WordPress sites and blogs. Both the free Social Warfare plugin and Social Warfare Pro are called out as affected.

Practical inventory steps:

Because exact vulnerable version ranges are not listed in the supplied facts, compare every discovered installation against the current vendor advisory before declaring a host clean or affected.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed package directly from the plugin vendor or the official WordPress plugin repository, install it on a staging copy if possible, then deploy to production. After updating, verify the plugin version in the admin UI or via the plugin header file.

Additional hardening appropriate to this vulnerability class:

If you can't patch immediately

If an immediate update is not possible, reduce exposure with compensating controls while you schedule the patch:

These measures lower risk but do not replace the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities of this type frequently lead to site defacement, credential theft, or installation of backdoors that can exfiltrate data. Known ransomware use is not documented for this CVE, yet any successful remote-code-execution path should be treated as a potential breach. Rotate WordPress and hosting credentials, review file integrity and user accounts, and examine logs for signs of persistence. You can run a free exposure scan of your email addresses against known breach data sets to determine whether associated credentials have appeared in prior incidents, then force password resets and enable multi-factor authentication wherever possible.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWordPress · Social Warfare Plugin
WeaknessCWE-79
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities