PT-2026-39497 · Accesspress Themes · Accesspress Social Icons

Murat Demirci

·

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2021-47910

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event handlers that execute when the plugin page is viewed, affecting all users who access the plugin interface.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47910

Affected Products

Accesspress Social Icons