Vulnerabilities and security researches forsocial-pug social-pug
Direction: ascendingJun 06, 2024
Hubbub Lite # CVE-2024-1526
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 01, 2024
- Research Description
- The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.
- Affected versions
-
max 1.33.1.
- Status
-
vulnerable
Hubbub Lite # CVE-2016-10736
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 10, 2019
- Research Description
- The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.
- Affected versions
-
max 1.2.6.
- Status
-
vulnerable
Hubbub Lite # CVE-2023-7154
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 16, 2024
- Research Description
- The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
max 1.32.0.
- Status
-
vulnerable
Hubbub Lite # CVE-2024-2501
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 10, 2024
- Research Description
- The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for authenticated attackers, with contributor access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
- Affected versions
-
max 1.33.2.
- Status
-
vulnerable
Jun 10, 2024
Hubbub Lite # CVE-2023-49193
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 09, 2024
- Research Description
- Missing Authorization vulnerability in NerdPress Hubbub Lite social-pug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hubbub Lite: from n/a through <= 1.30.0.
- Affected versions
-
max 1.30.1.
- Status
-
vulnerable
May 16, 2025
Hubbub Lite # CVE-2024-10145
- CVE, Research URL
- Home page URL
- Application
- Date
- May 16, 2025
- Research Description
- The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected versions
-
max 1.34.4.
- Status
-
vulnerable
Dec 11, 2025
Hubbub Lite # CVE-2025-12471
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 06, 2025
- Research Description
- The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dpsp_list_attention_search' parameter in all versions up to, and including, 1.36.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.36.1.
- Status
-
vulnerable
Apr 25, 2026
Hubbub Lite # CVE-2025-58007
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 23, 2025
- Research Description
- Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NerdPress Hubbub Lite social-pug allows Retrieve Embedded Sensitive Data.This issue affects Hubbub Lite: from n/a through <= 1.35.2.
- Affected versions
-
max 1.36.0.
- Status
-
vulnerable
Jun 16, 2026
Hubbub Lite # bd3bfce65262a0dd8cc9f6ed586ad15484a6c705
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 13, 2022
- Research Description
- Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.19.0 WordPress Grow Social plugin <= 1.18.2 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Grow Social plugin (versions <= 1.18.2). Update the WordPress Grow Social plugin to the latest available version (at least 1.19.0).
- Affected versions
-
max 1.19.0.
- Status
-
vulnerable
Hubbub Lite # b2f23bf0358d75d437485af10884044587ef5b81
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 09, 2023
- Research Description
- Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.2.6 WordPress Social Pug Plugin <= 1.2.5 is vulnerable to Cross Site Scripting (XSS) Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Social Pug Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.2.6.
- Affected versions
-
max 1.2.6.
- Status
-
vulnerable
Hubbub Lite # 80822739-4e95-46e8-a438-db99017948ee
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.19.0 Grow Social < 1.19.0 - Reflected Cross-Site Scripting The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected versions
-
max 1.19.0.
- Status
-
vulnerable
Hubbub Lite # bb8309d7fd2f6d9242f8ab77244e0496156cda2a
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 09, 2016
- Research Description
- Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.2.6 WordPress Social Pug Plugin <= 1.2.5 - Cross Site Scripting This plugin is prone to a cross site scripting vulnerability. It allows attackers to inject arbitrary JavaScript or HTML code. Update the plugin.
- Affected versions
-
max 1.2.6.
- Status
-
vulnerable
Hubbub Lite # 90f2b648bef4d9dd0be18b3f2650fcad20851cea
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 08, 2021
- Research Description
- Hubbub Lite – Fast, free social sharing and follow buttons [social-pug] < 1.19.0 Grow Social <= 1.18.2 - Reflected Cross-Site Scripting The Grow Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.18.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.19.0.
- Status
-
vulnerable
Jul 29, 2026
Hubbub Lite # CVE-2026-27403
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 23, 2026
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.
- Affected versions
-
max 1.36.3.1.
- Status
-
vulnerable