CVE-2025-5528
- EPSS 0.21%
- Veröffentlicht 07.06.2025 11:17:50
- Zuletzt bearbeitet 14.07.2025 17:26:28
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.75 due to insufficient input sanitization and outpu...
CVE-2025-39404
- EPSS 0.03%
- Veröffentlicht 24.04.2025 16:15:33
- Zuletzt bearbeitet 29.04.2025 13:52:28
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share allows Phishing. This issue affects Sassy Social Share: from n/a through 3.3.73.
CVE-2024-11252
- EPSS 44.16%
- Veröffentlicht 30.11.2024 06:15:17
- Zuletzt bearbeitet 09.07.2025 13:54:32
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and outpu...
CVE-2022-4971
- EPSS 1.19%
- Veröffentlicht 16.10.2024 07:15:12
- Zuletzt bearbeitet 30.10.2024 16:37:33
The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization...
CVE-2024-4924
- EPSS 0.44%
- Veröffentlicht 12.06.2024 06:15:09
- Zuletzt bearbeitet 30.05.2025 15:48:26
The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability ...
CVE-2024-2159
- EPSS 0.19%
- Veröffentlicht 26.04.2024 05:15:50
- Zuletzt bearbeitet 08.05.2025 19:14:42
The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and abo...
CVE-2024-1989
- EPSS 0.14%
- Veröffentlicht 06.03.2024 06:15:50
- Zuletzt bearbeitet 11.03.2025 16:41:12
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions up to, and including, 3.3.58 due to insufficient input sanitization and o...
CVE-2024-1448
- EPSS 0.15%
- Veröffentlicht 29.02.2024 01:43:51
- Zuletzt bearbeitet 08.01.2025 18:38:49
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.3.56 due to insufficient input sanitization and output escaping on ...
CVE-2022-4451
- EPSS 0.12%
- Veröffentlicht 16.01.2023 16:15:11
- Zuletzt bearbeitet 04.04.2025 18:15:44
The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting ...
CVE-2021-24746
- EPSS 4%
- Veröffentlicht 28.03.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:53:40
The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-...