Extension WordPress
Vulnérabilités Social Sharing Plugin – Sassy Social Share
Cette page rassemble les failles publiées pour Social Sharing Plugin – Sassy Social Share, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Social Sharing Plugin – Sassy Social Share
11 fiches
Social Sharing Plugin – Sassy Social Share <= 3.3.75 – Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.75 due to insufficient input sanitization and output escaping. This…
*-3.3.75
3.3.76
06/06/2025
Sassy Social Share <= 3.3.73 – Open Redirect
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.3.73. This is due to insufficient validation on a redirect url. This makes it possible…
*-3.3.73
3.3.74
17/04/2025
Social Sharing Plugin – Sassy Social Share <= 3.3.69 – Reflected Cross-Site Scripting via heateor_mastodon_share Parameter
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and output escaping. This…
*-3.3.69
3.3.70
29/11/2024
Sassy Social Share <= 3.3.62 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.62 due to insufficient input sanitization and output escaping. This makes…
*-3.3.62
3.3.63
22/05/2024
Sassy Social Share <= 3.3.60 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping on…
*-3.3.60
3.3.61
05/04/2024
Social Sharing Plugin – Sassy Social Share <= 3.3.58 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping…
*-3.3.58
3.3.59
05/03/2024
Sassy Social Share <= 3.3.56 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.3.56 due to insufficient input sanitization and output escaping on…
*-3.3.56
3.3.57
20/02/2024
Sassy Social Share <= 3.3.44 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous shortcode attributes (such as 'title' and 'width') used in the 'follow_icons_shortcode' and 'sharing_shortcode' functions in versions up to, and including, 3.3.44 due to…
*-3.3.44
3.3.45
21/12/2022
Sassy Social Share <= 3.3.3 – Reflected Cross-Site Scripting
The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping.…
*-3.3.3
3.3.4
29/11/2022
Sassy Social Share <= 3.3.39 – Reflected Cross-Site Scripting
The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a…
[*, 3.3.40)
3.3.40
15/03/2022
Sassy Social Share 3.3.23 – Object Injection
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file. This…
3.3.23
3.3.24
21/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.