Cross-site Scripting Vulnerability in Heateor Support Sassy Social Share Plugin
CVE-2026-94170

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-94170?

This vulnerability arises from an improper neutralization of input during the web page generation process, allowing malicious actors to inject and execute arbitrary scripts in a user's browser. Specifically, the Heateor Support Sassy Social Share plugin is susceptible to a reflected XSS attack in versions up to 3.3.79. When users interact with compromised links, it enables attackers to manipulate content, hijack sessions, and perform unauthorized actions on behalf of the users.

Affected Version(s)

Sassy Social Share 0 <= 3.3.79

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ChuongVN | Patchstack Bug Bounty Program
.