cleantalk
Vulnerabilities and Security Researches

Social Sharing Plugin – Sassy Social Share, CVE-2021-24746

CVE, Research URL

CVE-2021-24746

Published on
Mar 28, 2022
Research Description
The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.
Affected versions
Min -, max 3.3.4.
Status
vulnerable