Nextscripts
Nextscripts Social Networks Auto Poster: vulnerabilities and CVEs
Nextscripts Social Networks Auto Poster has 13 published vulnerabilities, 3 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs13
Last 12 months3
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97227 | Medium (5.9) | 0.19% | — | Sep 27, 2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has… |
| CVE-2026-16570 | High (7.1) | 0.25% | — | Aug 19, 2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected… |
| CVE-2026-3228 | Medium (6.4) | 0.33% | — | Mar 10, 2026 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in all versions up to, and including, 4.4.6. This is due to insufficient… |
| CVE-2020-36831 | Medium (6.5) | 0.50% | — | Oct 16, 2024 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and… |
| CVE-2024-37275 | Medium (6.1) | 0.31% | — | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows DOM-Based XSS.This issue affects… |
| CVE-2024-2088 | Medium (6.5) | 0.34% | — | May 22, 2024 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSettings' function. This makes it possible… |
| CVE-2024-1762 | Medium (6.1) | 0.39% | — | May 22, 2024 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_USER_AGENT header in all versions up to, and including, 4.4.3 due to insufficient input… |
| CVE-2024-1446 | Medium (4.3) | 0.18% | — | May 22, 2024 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing or incorrect nonce validation on the… |
| CVE-2023-49183 | Medium (6.1) | 0.40% | — | Dec 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.This issue affects NextScripts: Social… |
| CVE-2021-25072 | Medium (6.5) | 0.53% | — | Feb 1, 2022 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack |
| CVE-2021-24975 | Medium (6.1) | 1.3% | — | Feb 1, 2022 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored… |
| CVE-2021-38356 | Medium (6.1) | 0.87% | — | Nov 1, 2021 | The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the… |
| CVE-2019-9911 | Medium (6.1) | 1.3% | — | Mar 22, 2019 | The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.