cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsocial-pug social-pug

Direction: ascending
Jun 06, 2024

Hubbub Lite # CVE-2024-1526

CVE, Research URL

CVE-2024-1526

Application

Hubbub Lite

Date
Apr 01, 2024
Research Description
The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.
Affected versions
max 1.33.1.
Status
vulnerable

Hubbub Lite # CVE-2016-10736

CVE, Research URL

CVE-2016-10736

Application

Hubbub Lite

Date
Jan 10, 2019
Research Description
The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.
Affected versions
max 1.2.6.
Status
vulnerable

Hubbub Lite # CVE-2023-7154

CVE, Research URL

CVE-2023-7154

Application

Hubbub Lite

Date
Jan 16, 2024
Research Description
The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 1.32.0.
Status
vulnerable

Hubbub Lite # CVE-2024-2501

CVE, Research URL

CVE-2024-2501

Application

Hubbub Lite

Date
Apr 10, 2024
Research Description
The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for authenticated attackers, with contributor access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Affected versions
max 1.33.2.
Status
vulnerable
Jun 10, 2024

Hubbub Lite # CVE-2023-49193

CVE, Research URL

CVE-2023-49193

Application

Hubbub Lite

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in NerdPress Hubbub Lite social-pug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hubbub Lite: from n/a through <= 1.30.0.
Affected versions
max 1.30.1.
Status
vulnerable
May 16, 2025

Hubbub Lite # CVE-2024-10145

CVE, Research URL

CVE-2024-10145

Application

Hubbub Lite

Date
May 16, 2025
Research Description
The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.34.4.
Status
vulnerable
Dec 11, 2025

Hubbub Lite # CVE-2025-12471

CVE, Research URL

CVE-2025-12471

Application

Hubbub Lite

Date
Nov 06, 2025
Research Description
The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dpsp_list_attention_search' parameter in all versions up to, and including, 1.36.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.36.1.
Status
vulnerable
Apr 25, 2026

Hubbub Lite # CVE-2025-58007

CVE, Research URL

CVE-2025-58007

Application

Hubbub Lite

Date
Sep 23, 2025
Research Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NerdPress Hubbub Lite social-pug allows Retrieve Embedded Sensitive Data.This issue affects Hubbub Lite: from n/a through <= 1.35.2.
Affected versions
max 1.36.0.
Status
vulnerable
Jun 16, 2026

Hubbub Lite # bd3bfce65262a0dd8cc9f6ed586ad15484a6c705

Application

Hubbub Lite

Date
Jun 13, 2022
Research Description
Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.19.0 WordPress Grow Social plugin <= 1.18.2 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Grow Social plugin (versions <= 1.18.2). Update the WordPress Grow Social plugin to the latest available version (at least 1.19.0).
Affected versions
max 1.19.0.
Status
vulnerable

Hubbub Lite # b2f23bf0358d75d437485af10884044587ef5b81

Application

Hubbub Lite

Date
Dec 09, 2023
Research Description
Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.2.6 WordPress Social Pug Plugin <= 1.2.5 is vulnerable to Cross Site Scripting (XSS) Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Social Pug Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.2.6.
Affected versions
max 1.2.6.
Status
vulnerable

Hubbub Lite # 80822739-4e95-46e8-a438-db99017948ee

Application

Hubbub Lite

Date
-
Research Description
Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.19.0 Grow Social &lt; 1.19.0 - Reflected Cross-Site Scripting The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
Affected versions
max 1.19.0.
Status
vulnerable

Hubbub Lite # bb8309d7fd2f6d9242f8ab77244e0496156cda2a

Application

Hubbub Lite

Date
Dec 09, 2016
Research Description
Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.2.6 WordPress Social Pug Plugin <= 1.2.5 - Cross Site Scripting This plugin is prone to a cross site scripting vulnerability. It allows attackers to inject arbitrary JavaScript or HTML code. Update the plugin.
Affected versions
max 1.2.6.
Status
vulnerable

Hubbub Lite # 90f2b648bef4d9dd0be18b3f2650fcad20851cea

Application

Hubbub Lite

Date
Jul 08, 2021
Research Description
Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.19.0 Grow Social <= 1.18.2 - Reflected Cross-Site Scripting The Grow Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.18.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.19.0.
Status
vulnerable
Jul 29, 2026

Hubbub Lite # CVE-2026-27403

CVE, Research URL

CVE-2026-27403

Application

Hubbub Lite

Date
Jul 23, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.
Affected versions
max 1.36.3.1.
Status
vulnerable