The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019
Published Mar 24, 2019 ·Due May 3, 2022
6.1
MEDIUMCVSS 3.1
EPSS 72.95%
Description
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
Affected products
No data.
- < 3.5.3
- < 3.5.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Date Added
Nov 3, 2021
Patch Due
May 3, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (32 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 72.95% (0.72946) | 99.44th | v5 (v2026.06.15) |
| Jun 15, 2026 | 73.54% (0.73543) | 99.40th | v5 (v2026.06.15) |
| Nov 21, 2025 | 88.16% (0.88161) | 99.45th | v4 (v2025.03.14) |
| Nov 18, 2025 | 93.65% (0.93652) | 99.89th | v4 (v2025.03.14) |
| Oct 30, 2025 | 88.16% (0.88161) | 99.45th | v4 (v2025.03.14) |
| Oct 22, 2025 | 86.14% (0.86144) | 99.35th | v4 (v2025.03.14) |
| Jul 28, 2025 | 87.70% (0.87697) | 99.42th | v4 (v2025.03.14) |
| Jun 27, 2025 | 89.34% (0.89341) | 99.51th | v4 (v2025.03.14) |
| Jun 8, 2025 | 88.30% (0.88301) | 99.44th | v4 (v2025.03.14) |
| Jun 4, 2025 | 89.42% (0.89422) | 99.52th | v4 (v2025.03.14) |
| Mar 17, 2025 | 90.61% (0.90614) | 99.60th | v4 (v2025.03.14) |
| Dec 17, 2024 | 94.41% (0.94412) | 99.41th | v3 (v2023.03.01) |
| Dec 12, 2024 | 96.57% (0.96566) | 99.67th | v3 (v2023.03.01) |
| Apr 21, 2024 | 97.15% (0.97149) | 99.80th | v3 (v2023.03.01) |
| Feb 13, 2024 | 97.24% (0.97236) | 99.82th | v3 (v2023.03.01) |
| Jan 12, 2024 | 97.27% (0.97265) | 99.82th | v3 (v2023.03.01) |
| Nov 7, 2023 | 97.32% (0.97323) | 99.84th | v3 (v2023.03.01) |
| Sep 4, 2023 | 97.34% (0.97338) | 99.82th | v3 (v2023.03.01) |
| Aug 20, 2023 | 97.29% (0.97286) | 99.78th | v3 (v2023.03.01) |
| Aug 5, 2023 | 97.25% (0.97247) | 99.75th | v3 (v2023.03.01) |
| Jul 18, 2023 | 97.31% (0.97306) | 99.79th | v3 (v2023.03.01) |
| Jul 3, 2023 | 97.29% (0.97293) | 99.78th | v3 (v2023.03.01) |
| Jun 19, 2023 | 97.35% (0.97348) | 99.82th | v3 (v2023.03.01) |
| Mar 31, 2023 | 97.39% (0.97395) | 99.83th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.43% (0.97434) | 99.88th | v3 (v2023.03.01) |
| Mar 6, 2023 | 55.36% (0.55361) | 98.81th | v2 (v2022.01.01) |
| Feb 4, 2022 | 55.36% (0.55361) | 98.47th | v2 (v2022.01.01) |
| Feb 3, 2022 | 9.45% (0.09448) | 86.95th | v1 |
| Jan 6, 2022 | 9.45% (0.09448) | 86.79th | v1 |
| Sep 1, 2021 | 9.45% (0.09448) | 94.05th | v1 |
| Jul 28, 2021 | 9.45% (0.09448) | 0.00th | v1 |
| Apr 14, 2021 | 8.66% (0.08659) | 0.00th | v1 |
References (12)
- http://packetstormsecurity.com/files/152722/Wordpress-Social-Warfare-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/163680/WordPress-Social-Warfare-3.5.2-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2025/Jun/1 Mailing List
- https://blog.sucuri.net/2019/03/zero-day-stored-xss-in-social-warfare.html x_refsource_MISCExploitThird Party Advisory
- https://twitter.com/warfareplugins/status/1108852747099652099 x_refsource_MISCThird Party Advisory
- https://wordpress.org/plugins/social-warfare/#developers x_refsource_MISCProduct
- https://wpvulndb.com/vulnerabilities/9238 x_refsource_MISCBroken LinkThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9978 government-resourceUS Government Resource
- https://www.cybersecurity-help.cz/vdb/SB2019032105 x_refsource_MISCExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46794/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.pluginvulnerabilities.com/2019/03/21/full-disclosure-of-settings-change-persistent-cross-site-scripting-xss-vulnerability-in-social-warfare/ x_refsource_MISCExploitThird Party Advisory
- https://www.wordfence.com/blog/2019/03/unpatched-zero-day-vulnerability-in-social-warfare-plugin-exploited-in-the-wild/ x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.