Unintentional Cross-Site Scripting Vulnerability in Sassy Social Share Plugin
CVE-2024-11252
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 30 November 2024
Summary
The Sassy Social Share plugin for WordPress is subject to a vulnerability stemming from inadequate input sanitization and output escaping techniques. Specifically, the issue resides in the handling of the 'heateor_mastodon_share' parameter, present in all versions up to and including 3.3.69. This vulnerability permits unauthenticated attackers to inject arbitrary web scripts into web pages. If users can be manipulated into interacting with a malicious link, these scripts can execute in their browsers, posing significant security risks to web users and compromising the integrity of sites utilizing the plugin.
Affected Version(s)
Social Sharing Plugin – Sassy Social Share * <= 3.3.69
References
EPSS Score
51% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved