Heateor

Sassy Social Share

11 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Published 07.06.2025 11:17:50
  • Last modified 14.07.2025 17:26:28

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.75 due to insufficient input sanitization and outpu...

  • EPSS 0.03%
  • Published 24.04.2025 16:15:33
  • Last modified 29.04.2025 13:52:28

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share allows Phishing. This issue affects Sassy Social Share: from n/a through 3.3.73.

  • EPSS 44.16%
  • Published 30.11.2024 06:15:17
  • Last modified 09.07.2025 13:54:32

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and outpu...

Exploit
  • EPSS 1.19%
  • Published 16.10.2024 07:15:12
  • Last modified 30.10.2024 16:37:33

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization...

Exploit
  • EPSS 0.44%
  • Published 12.06.2024 06:15:09
  • Last modified 30.05.2025 15:48:26

The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability ...

Exploit
  • EPSS 0.19%
  • Published 26.04.2024 05:15:50
  • Last modified 08.05.2025 19:14:42

The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and abo...

  • EPSS 0.14%
  • Published 06.03.2024 06:15:50
  • Last modified 11.03.2025 16:41:12

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions up to, and including, 3.3.58 due to insufficient input sanitization and o...

  • EPSS 0.15%
  • Published 29.02.2024 01:43:51
  • Last modified 08.01.2025 18:38:49

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.3.56 due to insufficient input sanitization and output escaping on ...

Exploit
  • EPSS 0.12%
  • Published 16.01.2023 16:15:11
  • Last modified 04.04.2025 18:15:44

The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting ...

Exploit
  • EPSS 4%
  • Published 28.03.2022 18:15:08
  • Last modified 21.11.2024 05:53:40

The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-...