CVE Database /
CVE-2021-24746
CVE · Medium
CVE-2021-24746 — Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.40
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24746
|
Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.40 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 3.3.40
|
3.3.40 |
2022-03-15 |
—
|
CVE-2021-24746
The Sassy Social Share plugin before version 3.3.40 contains a reflected cross-site scripting vulnerability in its "More" icon feature, which is enabled by default. The plugin fails to properly sanitize the current page URL before inserting it into onclick attributes, allowing attackers to inject malicious scripts through specially crafted links. This flaw affects all installations with the vulnerable feature active and was remedied in version 3.3.40 following notification to the vendor in September 2021.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings