Unintentional Cross-Site Scripting Vulnerability in Sassy Social Share Plugin
CVE-2024-11252
6.1MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 30 November 2024
Summary
The Sassy Social Share plugin for WordPress is subject to a vulnerability stemming from inadequate input sanitization and output escaping techniques. Specifically, the issue resides in the handling of the 'heateor_mastodon_share' parameter, present in all versions up to and including 3.3.69. This vulnerability permits unauthenticated attackers to inject arbitrary web scripts into web pages. If users can be manipulated into interacting with a malicious link, these scripts can execute in their browsers, posing significant security risks to web users and compromising the integrity of sites utilizing the plugin.
Affected Version(s)
Social Sharing Plugin – Sassy Social Share * <= 3.3.69
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Mazzolini