PLUGIN SECURITY
Is Sassy Social Share safe?
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
What this plugin does
- Slug:
sassy-social-share - Author: Heateor Support
- 100000+ active installs
- 96/100 rating (522 reviews on wordpress.org)
- 6897648 all-time downloads
- On WordPress.org since 2015-12-03
ChatGPTgroksocial mediasocial shareSocial Share Buttons
Maintenance status
- Latest known version: 3.3.79
- Last updated: 2025-09-15 10:28am GMT
- Tested up to WordPress: 6.8.8
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
11 known CVEs on file for Sassy Social Share.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-39404 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.74 | URL Redirection to Untrusted Site ('Open Redirect') | Medium 4.7 | < 3.3.74 | 3.3.74 | 2025-04-17 | ✓ fixed in latest |
| CVE-2024-11252 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.70 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.3.70 | 3.3.70 | 2024-11-29 | ✓ fixed in latest |
| CVE-2024-4924 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.63 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.3.63 | 3.3.63 | 2024-05-22 | ✓ fixed in latest |
| CVE-2024-2159 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.61 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.7 | < 3.3.61 | 3.3.61 | 2024-04-05 | ✓ fixed in latest |
| CVE-2024-1989 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.59 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.3.59 | 3.3.59 | 2024-03-05 | ✓ fixed in latest |
| CVE-2024-1448 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.57 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.3.57 | 3.3.57 | 2024-02-20 | ✓ fixed in latest |
| CVE-2022-4451 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.45 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.3.45 | 3.3.45 | 2022-12-21 | ✓ fixed in latest |
| CVE-2022-4971 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.3.4 | 3.3.4 | 2022-11-29 | ✓ fixed in latest |
+ 7 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2021-24746 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.40 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.3.40 | 3.3.40 | 2022-03-15 | ✓ fixed in latest |
| CVE-2021-39321 | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.40 | Deserialization of Untrusted Data | High 8.8 | < 3.3.40 | 3.3.40 | 2021-10-20 | ✓ fixed in latest |
| — | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.4 | — | Unknown | < 3.3.4 | 3.3.4 | 2019-11-18 | ✓ fixed in latest |
| — | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.76 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.3.76 | 3.3.76 | 0000-00-00 | ✓ fixed in latest |
| — | Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.4 | — | Unknown | < 3.3.4 | 3.3.4 | — | ✓ fixed in latest |
| — | Sassy Social Share <= 3.3.3 - Cross-Site Scripting (XSS) | — | Unknown | < 3.3.4 | 3.3.4 | — | ✓ fixed in latest |
| CVE-2025-5528 | Social Sharing Plugin – Sassy Social Share < 3.3.76 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter | — | Unknown | < 3.3.76 | 3.3.76 | — | ✓ fixed in latest |
How to fix it
Keep Sassy Social Share updated — 3.3.79 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- LocoAI – Auto Translate for Loco Translate — 70000+ active installs — 98/100 (637) — max PHP 8.4
- Chat Button & Custom ChatGPT-Powered Bot by GetButton.io — 20000+ active installs — 90/100 (175) — max PHP 8.4
- WPVibe – WordPress MCP Server. Connect Claude, ChatGPT & Any AI Agent via MCP — 10000+ active installs — 98/100 (25) — max PHP 8.4
- Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP — 10000+ active installs — 100/100 (7) — max PHP 8.4
- Easy MCP AI – Connector for Claude, ChatGPT & SEO Data — 8000+ active installs — 100/100 (8)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.