Unintentional Cross-Site Scripting Vulnerability in Sassy Social Share Plugin
CVE-2024-11252

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
30 November 2024

Summary

The Sassy Social Share plugin for WordPress is subject to a vulnerability stemming from inadequate input sanitization and output escaping techniques. Specifically, the issue resides in the handling of the 'heateor_mastodon_share' parameter, present in all versions up to and including 3.3.69. This vulnerability permits unauthenticated attackers to inject arbitrary web scripts into web pages. If users can be manipulated into interacting with a malicious link, these scripts can execute in their browsers, posing significant security risks to web users and compromising the integrity of sites utilizing the plugin.

Affected Version(s)

Social Sharing Plugin – Sassy Social Share * <= 3.3.69

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Mazzolini
.