Vulnerabilities and security researches forsocial-pug social-pug
Direction: ascendingJun 06, 2024
Hubbub Lite # CVE-2024-1526
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 01, 2024
- Research Description
- The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Hubbub Lite # CVE-2016-10736
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 10, 2019
- Research Description
- The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Hubbub Lite # CVE-2023-7154
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 16, 2024
- Research Description
- The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Hubbub Lite # CVE-2024-2501
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 10, 2024
- Research Description
- The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for authenticated attackers, with contributor access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 10, 2024
Hubbub Lite # CVE-2023-49193
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 09, 2024
- Research Description
- Missing Authorization vulnerability in NerdPress Social Pug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Pug: from n/a through 1.30.0.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
May 16, 2025
Hubbub Lite # CVE-2024-10145
- CVE, Research URL
- Home page URL
- Application
- Date
- May 16, 2025
- Research Description
- The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected versions
-
Min -, max -.
- Status
-
vulnerable