{"id":"CVE-2023-0377","summary":"Scriptless Social Sharing \u003c 3.2.2 - Contributor+ Stored XSS","details":"The Scriptless Social Sharing WordPress plugin before 3.2.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.","modified":"2026-08-12T03:51:41.291071118Z","published":"2023-03-06T13:34:05.264Z","database_specific":{"cna_assigner":"WPScan","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/0xxx/CVE-2023-0377.json","unresolved_ranges":[{"extracted_events":[{"fixed":"3.2.2"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"3.2.2"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://wordpress.org/plugins"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/0xxx/CVE-2023-0377.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0377"},{"type":"EVIDENCE","url":"https://wpscan.com/vulnerability/5b1aacd1-3f75-4a6f-8146-cbb98a713724"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/robincornett/scriptless-social-sharing","events":[{"introduced":"0"},{"fixed":"626ddedfa0d9d324a72d01cb613f85932f531149"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.2.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:robincornett:scriptless_social_sharing:*:*:*:*:*:wordpress:*:*"}}],"versions":["3.2.1","3.2.0","3.1.6","3.1.5","3.1.4","3.1.3","3.1.2","3.1.1","3.1.0","3.0.1","3.0.0","2.3.0","2.2.2","2.2.1","2.2.0","2.1.1","2.1.0","2.0.1","2.0.0","1.5.2","1.5.1","1.5.0","1.4.0","1.3.0","1.2.2","1.2.1","1.2.0","1.1.0","1.0.2","1.0.1","1.0.0","0.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-0377.json"}}],"schema_version":"1.9.0"}