
CVE-2026-2501 The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` shortcode in all versions up to, and including, … https://www.cve.org/CVERecord?id=CVE-2026-2501
Post summary
The Ed's Social Share plugin for WordPress is disclosed as vulnerable to stored XSS through its `social_share` shortcode, affecting all versions up to the referenced CVE-2026-2501.
