Known Vulnerabilities for Social Pug Wordpress by Nerdpress
Listed below are 10 of the newest known vulnerabilities associated with "Social Pug Wordpress" by "Nerdpress".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-5425 json | The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' param... | Not Provided | 2026-04-04 | 2026-04-06 |
| CVE-2026-5231 json | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all ver... | Not Provided | 2026-04-17 | 2026-04-17 |
| CVE-2026-4331 json | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all versi... | Not Provided | 2026-03-26 | 2026-03-26 |
| CVE-2026-4330 json | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through user-c... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-4085 json | The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class' shor... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2026-4063 json | The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missi... | Not Provided | 2026-03-13 | 2026-04-08 |
| CVE-2026-3228 json | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_... | Not Provided | 2026-03-10 | 2026-04-08 |
| CVE-2026-3226 json | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized email notification triggering due ... | Not Provided | 2026-03-12 | 2026-04-08 |
| CVE-2026-2991 json | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all ... | Not Provided | 2026-03-18 | 2026-04-08 |
| CVE-2026-2501 json | The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` short... | Not Provided | 2026-03-21 | 2026-04-08 |