CVE · Medium

CVE-2021-24746 — Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.40

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24746 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.40 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.3.40 3.3.40 2022-03-15

CVE-2021-24746

The Sassy Social Share plugin before version 3.3.40 contains a reflected cross-site scripting vulnerability in its "More" icon feature, which is enabled by default. The plugin fails to properly sanitize the current page URL before inserting it into onclick attributes, allowing attackers to inject malicious scripts through specially crafted links. This flaw affects all installations with the vulnerable feature active and was remedied in version 3.3.40 following notification to the vendor in September 2021.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.