PT-2025-31737 · WordPress · Ocean Social Sharing
Muhammad Yudha
·
Published
2025-08-02
·
Updated
2025-08-02
·
CVE-2025-7500
CVSS v3.1
6.4
6.4
Medium
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Ocean Social Sharing plugin for WordPress versions prior to 2.2.2
Description:
The Ocean Social Sharing plugin for WordPress is susceptible to Stored Cross-Site Scripting through social icon titles due to insufficient input sanitization and output escaping. This allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page.
Recommendations:
Update the Ocean Social Sharing plugin to version 2.2.2 or later.
Fix
XSS
Weakness Enumeration
Related Identifiers
CVE-2025-7500
Affected Products
Ocean Social Sharing
References · 11
- https://nvd.nist.gov/vuln/detail/CVE-2025-7500 · Security Note
- https://t.me/cveNotify/130671 · Telegram Post
- https://t.me/CVEtracker/29017 · Telegram Post
- https://plugins.trac.wordpress.org/browser/ocean-social-sharing/tags/2.2.1/template/social-share.php#L262 · Note
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3331993%40ocean-social-sharing&new=3331993%40ocean-social-sharing&sfp_email=&sfph_mail= · Note
- https://plugins.trac.wordpress.org/browser/ocean-social-sharing/tags/2.2.1/template/social-share.php#L176 · Note
- https://plugins.trac.wordpress.org/browser/ocean-social-sharing/tags/2.2.1/template/social-share.php#L100 · Note
- https://plugins.trac.wordpress.org/browser/ocean-social-sharing/tags/2.2.1/template/social-share.php#L84 · Note
- https://twitter.com/VulmonFeeds/status/1951623946173906955 · Twitter Post
- https://twitter.com/CVEnew/status/1951609464122998895 · Twitter Post
- https://wordfence.com/threat-intel/vulnerabilities/id/7683e708-b7cb-444e-9069-f33e4ef3ac76?source=cve · Note