Lucene search

K
wpvulndbPaul J. MartinezWPVDB-ID:99F4FB32-E312-4059-ADAF-F4CBAA92D4FA
HistoryMar 15, 2022 - 12:00 a.m.

Sassy Social Share < 3.3.40 - Reflected Cross-Site Scripting

2022-03-1500:00:00
Paul J. Martinez
wpscan.com
13

0.001 Low

EPSS

Percentile

43.5%

The plugin does not escape the viewed post URL before outputting it back in onclick attributes when the “Enable ‘More’ icon” option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue. Note: Vendor was notified on September 14th, 2021.

PoC

https://example.com/any-post/?a&quot;&gt;&lt;script&gt;alert(/XSS/)&lt;/script&gt;

CPENameOperatorVersion
sassy-social-sharelt3.3.40

0.001 Low

EPSS

Percentile

43.5%

Related for WPVDB-ID:99F4FB32-E312-4059-ADAF-F4CBAA92D4FA