PLUGIN SECURITY

Is Sassy Social Share safe?

The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.

What this plugin does

  • Slug: sassy-social-share
  • Author: Heateor Support
  • 100000+ active installs
  • 96/100 rating (522 reviews on wordpress.org)
  • 6897648 all-time downloads
  • On WordPress.org since 2015-12-03

ChatGPTgroksocial mediasocial shareSocial Share Buttons

Maintenance status

  • Latest known version: 3.3.79
  • Last updated: 2025-09-15 10:28am GMT
  • Tested up to WordPress: 6.8.8
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

11 known CVEs on file for Sassy Social Share.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-39404 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.74 URL Redirection to Untrusted Site ('Open Redirect') Medium 4.7 < 3.3.74 3.3.74 2025-04-17 ✓ fixed in latest
CVE-2024-11252 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.70 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.3.70 3.3.70 2024-11-29 ✓ fixed in latest
CVE-2024-4924 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.63 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.3.63 3.3.63 2024-05-22 ✓ fixed in latest
CVE-2024-2159 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.61 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.7 < 3.3.61 3.3.61 2024-04-05 ✓ fixed in latest
CVE-2024-1989 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.59 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.3.59 3.3.59 2024-03-05 ✓ fixed in latest
CVE-2024-1448 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.57 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.3.57 3.3.57 2024-02-20 ✓ fixed in latest
CVE-2022-4451 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.45 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.3.45 3.3.45 2022-12-21 ✓ fixed in latest
CVE-2022-4971 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.3.4 3.3.4 2022-11-29 ✓ fixed in latest
+ 7 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24746 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.40 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.3.40 3.3.40 2022-03-15 ✓ fixed in latest
CVE-2021-39321 Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.40 Deserialization of Untrusted Data High 8.8 < 3.3.40 3.3.40 2021-10-20 ✓ fixed in latest
Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.4 Unknown < 3.3.4 3.3.4 2019-11-18 ✓ fixed in latest
Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.76 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.3.76 3.3.76 0000-00-00 ✓ fixed in latest
Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.4 Unknown < 3.3.4 3.3.4 ✓ fixed in latest
Sassy Social Share <= 3.3.3 - Cross-Site Scripting (XSS) Unknown < 3.3.4 3.3.4 ✓ fixed in latest
CVE-2025-5528 Social Sharing Plugin – Sassy Social Share < 3.3.76 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter Unknown < 3.3.76 3.3.76 ✓ fixed in latest

How to fix it

Keep Sassy Social Share updated — 3.3.79 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.