The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to stored cross-site scripting (XSS) in versions up to and including 4.4.6 via the [nxs_fbembed] shortcode. The issue stems from insufficient input sanitization and output escaping of the snapFB post meta value, allowing an authenticated attacker (Contributor role or higher) to persistently inject arbitrary JavaScript/HTML into content rendered by the shortcode. The injected script executes in victims’ browsers when they view an affected page/post.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
[nxs_fbembed] shortcode; limit Contributor access and review/approve contributor content before publication. Monitor and audit post meta (notably snapFB) and content for unexpected script/HTML. Deploy a restrictive Content Security Policy (CSP) to reduce XSS impact where feasible, and use a WAF rule to detect/block suspicious shortcode/meta payloads until patching is completed.Patch, then assume compromise.
snapFB post meta on input and escapes it on output in the [nxs_fbembed] rendering path. Ensure shortcode handlers apply WordPress-appropriate escaping (e.g., esc_url, esc_attr, esc_html, wp_kses as appropriate) and validate/normalize stored meta before use.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit tool (CVE-2026-3228.py) plus a README. The script is an end-to-end scanner/exploit for a stored XSS in the WordPress plugin “NextScripts: Social Networks Auto-Poster” (<= 4.4.6), abusing the [nxs_fbembed] shortcode and unsafe handling of the snapFB post meta. Core capabilities: - Pre-auth scanning to identify the plugin/version (as described in README; code includes HTTP interactions and parsing). - Authenticated checks: logs into WordPress with provided credentials, maintains a session, and verifies the user has sufficient privileges (Contributor+) to create posts. - Exploitation: generates multiple JavaScript payload variants (alert PoC, cookie exfiltration to a user-provided callback URL, admin-creation attempt, HTML/onerror style injection, custom JS, or “all” to create multiple posts). - Injection workflow: attempts to create a new post via the WordPress REST API endpoint /wp-json/wp/v2/posts first; if that fails, falls back to classic wp-admin editor flow by fetching /wp-admin/post-new.php to extract nonces and submitting to /wp-admin/post.php. - Trigger guidance: prints the created post URL (or /?p=<id> fallback) and notes that an administrator viewing the post will execute the stored script; optionally opens a browser for the alert payload. Notable operational details: - Uses requests.Session with SSL verification disabled and suppresses warnings (useful against self-signed targets). - Relies on WordPress endpoints (/wp-login.php, /wp-admin/*, REST API) and HTML parsing (BeautifulSoup) for nonce/flow handling. Overall purpose: a practical, interactive exploitation utility that both detects and weaponizes stored XSS for post-exploitation actions in the victim’s browser context (session theft and potential privilege escalation via admin creation), rather than a simple detection-only script.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.