Warfareplugins develops a social-media marketing plugin suite (Social Warfare and Social Warfare Pro) that integrates with WordPress, presenting an application-layer attack surface centered on web-facing input handling. Its observed vulnerability pattern centers on cross-site scripting, cross-site request forgery, code injection, and authorization control—weakness classes typical of plugins that process user-supplied content and interact with third-party social platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Warfareplugins over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9978MEDIUM The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019 | Mar 24, 2019 | 6.1 | 94 | YES | YES |
CVE-2021-4434CRITICAL The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute | Jan 17, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-26973MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WarfarePlugins Social Warfare social-warfare allows DOM-Based XSS.This issue a | Feb 22, 2025 | 6.5 | 20 | NO | NO |
CVE-2023-4842MEDIUM The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 | Nov 7, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0402MEDIUM The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. Thi | Jan 19, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-34825MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: from n/a through 4.4.5.1. | May 14, 2024 | 4.3 | 15 | NO | NO |
CVE-2023-0403MEDIUM The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing or incorrect nonce validation on | Jan 19, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Warfareplugins.
Media articles that mention a CVE ID that affects a product developed by Warfareplugins — matched by CVE ID, not by vendor name.