{"id":"CVE-2019-9978","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-9978","summary":null,"details":"The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.","published":"2019-03-24T15:29:00.243Z","modified":"2026-07-08T05:53:49.311514708Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.72946,"percentile":0.99409,"asOf":"2026-08-27"},"cisaKev":{"dateAdded":"2021-11-03","dueDate":"2022-05-03","knownRansomwareCampaignUse":false},"exploitsKnown":19,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://wordpress.org/plugins/social-warfare/#developers"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9978"},{"type":"ADVISORY","url":"https://twitter.com/warfareplugins/status/1108852747099652099"},{"type":"ADVISORY","url":"https://wpvulndb.com/vulnerabilities/9238"},{"type":"ADVISORY","url":"https://www.exploit-db.com/exploits/46794/"},{"type":"ADVISORY","url":"https://www.wordfence.com/blog/2019/03/unpatched-zero-day-vulnerability-in-social-warfare-plugin-exploited-in-the-wild/"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2025/Jun/1"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/152722/Wordpress-Social-Warfare-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/163680/WordPress-Social-Warfare-3.5.2-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"https://blog.sucuri.net/2019/03/zero-day-stored-xss-in-social-warfare.html"},{"type":"EVIDENCE","url":"https://www.cybersecurity-help.cz/vdb/SB2019032105"},{"type":"EVIDENCE","url":"https://www.pluginvulnerabilities.com/2019/03/21/full-disclosure-of-settings-change-persistent-cross-site-scripting-xss-vulnerability-in-social-warfare/"}],"provenance":{"sources":["OSV.dev","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:53:49.311514708Z"}}