Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress Social Rocket plugin to the latest available version (at least 1.3.6).
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthenticated Cross Site Scripting (XSS) in Social Rocket <= 1.3.5 versions. | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Socialrocket Social Rocket social-rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.5. |
Tue, 06 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress-extensions
Wordpress-extensions social Rocket Wpsocialrocket Wpsocialrocket social Rocket |
|
| Vendors & Products |
Wordpress-extensions
Wordpress-extensions social Rocket Wpsocialrocket Wpsocialrocket social Rocket |
Tue, 06 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthenticated Cross Site Scripting (XSS) in Social Rocket <= 1.3.5 versions. | |
| Title | WordPress Social Rocket plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-07T07:41:55.087Z
Reserved: 2026-04-27T10:39:10.016Z
Link: CVE-2026-42418
Updated: 2026-10-06T10:28:51.626Z
Status : Deferred
Published: 2026-10-06T09:17:54.900
Modified: 2026-10-07T08:16:57.203
Link: CVE-2026-42418
No data.
OpenCVE Enrichment
Updated: 2026-10-07T10:15:15Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')