cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsocial-pug social-pug

Direction: descending
May 16, 2025

Hubbub Lite # CVE-2024-10145

CVE, Research URL

CVE-2024-10145

Application

Hubbub Lite

Date
May 16, 2025
Research Description
The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Hubbub Lite # CVE-2023-49193

CVE, Research URL

CVE-2023-49193

Application

Hubbub Lite

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in NerdPress Social Pug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Pug: from n/a through 1.30.0.
Affected versions
Min -, max -.
Status
vulnerable
Jun 06, 2024

Hubbub Lite # CVE-2024-1526

CVE, Research URL

CVE-2024-1526

Application

Hubbub Lite

Date
Apr 01, 2024
Research Description
The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.
Affected versions
Min -, max -.
Status
vulnerable

Hubbub Lite # CVE-2016-10736

CVE, Research URL

CVE-2016-10736

Application

Hubbub Lite

Date
Jan 10, 2019
Research Description
The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.
Affected versions
Min -, max -.
Status
vulnerable

Hubbub Lite # CVE-2023-7154

CVE, Research URL

CVE-2023-7154

Application

Hubbub Lite

Date
Jan 16, 2024
Research Description
The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable

Hubbub Lite # CVE-2024-2501

CVE, Research URL

CVE-2024-2501

Application

Hubbub Lite

Date
Apr 10, 2024
Research Description
The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for authenticated attackers, with contributor access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Affected versions
Min -, max -.
Status
vulnerable