Lucene search

K
wpexploitPaul J. MartinezWPEX-ID:99F4FB32-E312-4059-ADAF-F4CBAA92D4FA
HistoryMar 15, 2022 - 12:00 a.m.

Sassy Social Share < 3.3.40 - Reflected Cross-Site Scripting

2022-03-1500:00:00
Paul J. Martinez
171

0.001 Low

EPSS

Percentile

43.5%

The plugin does not escape the viewed post URL before outputting it back in onclick attributes when the “Enable ‘More’ icon” option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue. Note: Vendor was notified on September 14th, 2021.

https://example.com/any-post/?a&quot;&gt;&lt;script&gt;alert(/XSS/)&lt;/script&gt;

0.001 Low

EPSS

Percentile

43.5%

Related for WPEX-ID:99F4FB32-E312-4059-ADAF-F4CBAA92D4FA