Easy Social Box / Page Plugin
Easy Social Box / Page Plugin has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Easy Social Box / Page Plugin has a vendor fix available, so running the current release closes it.
All of these findings were reported by István Márton. Easy Social Box / Page Plugin is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2022-4754Easy Social Box / Page Plugin <= 4.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records

Easy Social Box / Page Plugin
Author
iamshehryar
Easy Social box display facebook like box. it enable Facebook Page owners to attract and gain Likes from their own website. The Social Box enables users to see page likes, recent posts from the page and Like button and which of friends like this page too. Options Facebook Page URL – enter an URL address of your Facebook fan page. Width – set the width of the like box in pixels. Height – Set the height of like box in pixels. Show Faces – choose show or hide faces. Posts – choose show or hide lastest posts from your facebook fan page. Cover Photo – choose show or hide Cover Photo. Support different locales. Shortcode Now Shortcode is available in Easy Social Box and User can easily create shortcode by using widget. [easy-fb-like-box url=”enter your facebook page url” width=”set your width” height=”set your height” theme=”choose one theme light or dark” faces=”choose true or false” header=”choose ture or false” posts=”choose true or false” border=”choose true or false”] Follow Me Facebook
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C