← back to popular plugins
wordfence / plugin · sassy-social-share
Social Sharing Plugin – Sassy Social Share
sassy-social-share
total installs
100,000
total vulns
2
critical
0
high
0
medium
2
low
0
latest vuln
—
patched
2
unpatched
0
avg time to patch
—
vulnerabilities
(2)
Social Sharing Plugin – Sassy Social Share <= 3.3.75 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter
medium
✓ patched
cve id
CVE-2025-5528 ↗
cvss score
6.1
cwe
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published
Jun 6, 2025
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action, such as clicking on a link.
Sassy Social Share <= 3.3.73 - Open Redirect
medium
✓ patched
cve id
CVE-2025-39404 ↗
cvss score
6.1
cwe
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
published
Apr 17, 2025
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.3.73. This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.