CVE-2022-4451: Sassy Social Share < 3.3.45 - Contributor+ Stored XSS
Published Jan 16, 2023
·Updated
The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
1 affected component
Heateor Sassy Social Share WordPress<3.3.45
Event History
Jan 16, 2023
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-4451.
2
What is the severity of CVE-2022-4451?
The severity of CVE-2022-4451 is medium with a CVSS score of 5.4.
3
What software is affected by CVE-2022-4451?
The Social Sharing WordPress plugin before version 3.3.45 is affected by CVE-2022-4451.
4
What is the risk associated with CVE-2022-4451?
CVE-2022-4451 allows users with low privileges, such as contributors, to perform Stored Cross-Site Scripting attacks.
5
What is the fix for CVE-2022-4451?
To fix CVE-2022-4451, update the Social Sharing WordPress plugin to version 3.3.45 or later.