CVE-2021-39321: Sassy Social Share 3.3.23 PHP Object Injection
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wpajaxheateorsssimportconfig AJAX action due to deserialization of unvalidated user supplied inputs via the importconfig function found in the ~/admin/class-sassy-social-share-admin.php file. This can be exploited by underprivileged authenticated users due to a missing capability check on the importconfig function.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-39321?
CVE-2021-39321 is a vulnerability in version 3.3.23 of the Sassy Social Share WordPress plugin.
What is the severity of CVE-2021-39321?
CVE-2021-39321 has a severity rating of 8.8 (high).
How does CVE-2021-39321 affect the Sassy Social Share plugin?
CVE-2021-39321 allows for PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action, due to deserialization of unvalidated user supplied inputs via the import_config function in the ~/admin/class-sassy-social-share-admin.php file.
How can I fix CVE-2021-39321?
To fix CVE-2021-39321, update Sassy Social Share plugin to a version that has patched the vulnerability, such as version 3.3.24 or later.
Where can I find more information about CVE-2021-39321?
You can find more information about CVE-2021-39321 in the WordPress plugins.trac and Wordfence vulnerability advisories.