Record summary

CVE-2021-24746 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Social Sharing Plugin – Sassy Social Share

CVE List3.3.40 to < 3.3.40affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Sassy Social Share Plugin <3.3.40 - Cross-Site ScriptingCVSS 6.1

WordPress plugin Sassy Social Share < 3.3.40 contains a reflected cross-site scripting vulnerability.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential data theft, session hijacking, or defacement.

Remediation

Update the WordPress Sassy Social Share Plugin to version 3.3.40 or later to mitigate the vulnerability.

WeaknessesCWE-79
AuthorsSupras
Template tagscvecve2021wordpresswp-pluginxsswpwpscanheateorvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:heateor:sassy_social_share:*:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/sassy-social-share"

Source: ProjectDiscovery

References

2