CVE · Medium

CVE-2025-39404 — Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.74

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-39404 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.74 URL Redirection to Untrusted Site ('Open Redirect') Medium 4.7 < 3.3.74 3.3.74 2025-04-17

CVE-2025-39404

The Sassy Social Share plugin for WordPress has a flaw in its handling of redirects, allowing anyone to send users to any website without needing authentication. This is because the plugin doesn't properly check URLs before sending users there, making it easy to trick people into visiting malicious sites by exploiting this weakness. The issue affects all versions up to 3.3.73.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.