SecAlerts
h

heateor

Security Risk Profile

48
/100
medium

Security Risk Score

Comprehensive risk assessment based on 28 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from October 21, 2021 to present

28
Total CVEs
5
Critical+High
0
Exploited
1
Unpatched

Threat Assessment

Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
48/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
5
Medium
23
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
7

Age Distribution

Common Weaknesses (CWE)

1
XSS
22
2
SQL Injection
1

Most Affected Products

1. Heateor Sassy Social Share WordPress10
2. Heateor Super Socializer Wordpress7
3. Heateor Social Login WordPress5
4. Heateor Sassy Social Share3
5. Sassy Social Share Social Sharing Plugin2

Recent Vulnerabilities

See more →
CVE-2026-94170
CVSS 7.1high

WordPress Sassy Social Share plugin <= 3.3.79 - Cross Site Scripting (XSS) vulnerability

Oct 9, 2026🔧 No Patch
CVE-2025-9857
CVSS 6.4EPSS 0%medium

Heateor Login – Social Login Plugin <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 10, 2025🔧 No Patch
CVE-2025-5528
CVSS 6.1EPSS 0%medium

Social Sharing Plugin – Sassy Social Share <= 3.3.75 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter

Jun 7, 2025🔧 No Patch
CVE-2025-39404
CVSS 4.7EPSS 0%medium

WordPress Sassy Social Share plugin <= 3.3.73 - Open Redirection vulnerability

Apr 24, 2025
CVE-2024-13230
CVSS 5.3medium

Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.14 - Unauthenticated Limited SQL Injection via 'SuperSocializerKey'

Jan 21, 2025
CVE-2023-41802
CVSS 4.3medium

WordPress Super Socializer plugin <= 7.13.54 - Broken Access Control vulnerability

Dec 13, 2024
CVE-2024-11252
CVSS 6.1medium

Social Sharing Plugin – Sassy Social Share <= 3.3.69 - Reflected Cross-Site Scripting via heateor_mastodon_share Parameter

Nov 30, 2024🔧 No Patch
CVE-2024-9946
CVSS 8.1EPSS 0%high

Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.68 - Authentication Bypass via Disqus OAuth provider

Nov 6, 2024
CVE-2024-10020
CVSS 8.1high

Heateor Social Login WordPress <= 1.1.35 - Authentication Bypass via Disqus OAuth provider

Nov 6, 2024
CVE-2022-4971
CVSS 6.1medium

Sassy Social Share <= 3.3.3 - Reflected Cross-Site Scripting

Oct 16, 2024🔧 No Patch

Monitor heateor in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

heateor Security Vulnerabilities & Risk Score | 28 CVEs | SecAlerts - SecAlerts