cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsocial-networks-auto-poster-facebook-twitter-g social-networks-auto-poster-facebook-twitter-g

Direction: descending
Mar 29, 2026

NextScripts: Social Networks Auto-Poster # CVE-2026-27379

CVE, Research URL

CVE-2026-27379

Date
Mar 05, 2026
Research Description
Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7.
Affected versions
max 4.4.7.
Status
vulnerable
Oct 18, 2024

NextScripts: Social Networks Auto-Poster # CVE-2020-36831

CVE, Research URL

CVE-2020-36831

Date
Oct 16, 2024
Research Description
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user.
Affected versions
max 4.3.18.
Status
vulnerable
Jul 01, 2024

NextScripts: Social Networks Auto-Poster # CVE-2024-37275

CVE, Research URL

CVE-2024-37275

Date
Jul 22, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NextScripts allows Reflected XSS.This issue affects NextScripts: from n/a through 4.4.6.
Affected versions
max 4.4.6.
Status
vulnerable
Jun 07, 2024

NextScripts: Social Networks Auto-Poster # CVE-2019-9911

CVE, Research URL

CVE-2019-9911

Date
Mar 22, 2019
Research Description
The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS.
Affected versions
max 3.4.18.
Status
vulnerable

NextScripts: Social Networks Auto-Poster # CVE-2021-24975

CVE, Research URL

CVE-2021-24975

Date
Feb 01, 2022
Research Description
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue
Affected versions
max 4.3.25.
Status
vulnerable

NextScripts: Social Networks Auto-Poster # CVE-2021-25072

CVE, Research URL

CVE-2021-25072

Date
Feb 01, 2022
Research Description
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack
Affected versions
max 4.3.25.
Status
vulnerable

NextScripts: Social Networks Auto-Poster # CVE-2021-38356

CVE, Research URL

CVE-2021-38356

Date
Nov 02, 2021
Research Description
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript in $_POST['page'].
Affected versions
max 4.3.25.
Status
vulnerable

NextScripts: Social Networks Auto-Poster # CVE-2024-1762

CVE, Research URL

CVE-2024-1762

Date
May 22, 2024
Research Description
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_USER_AGENT header in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the victim to select view "All Cron Events" in order for the injection to fire.
Affected versions
max 4.4.4.
Status
vulnerable

NextScripts: Social Networks Auto-Poster # CVE-2024-1446

CVE, Research URL

CVE-2024-1446

Date
May 22, 2024
Research Description
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing or incorrect nonce validation on the nxssnap-reposter page. This makes it possible for unauthenticated attackers to delete arbitrary posts or pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 4.4.4.
Status
vulnerable

NextScripts: Social Networks Auto-Poster # CVE-2023-49183

CVE, Research URL

CVE-2023-49183

Date
Dec 15, 2023
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.This issue affects NextScripts: Social Networks Auto-Poster: from n/a through 4.4.2.
Affected versions
max 4.4.3.
Status
vulnerable

NextScripts: Social Networks Auto-Poster # CVE-2024-2088

CVE, Research URL

CVE-2024-2088

Date
May 22, 2024
Research Description
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSettings' function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including social network API keys and secrets.
Affected versions
max 4.4.4.
Status
vulnerable