CVE-2022-4971: Sassy Social Share <= 3.3.3 - Reflected Cross-Site Scripting
The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateorssssharingcount' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4971?
CVE-2022-4971 has a medium severity rating due to its potential for reflected cross-site scripting vulnerabilities.
How do I fix CVE-2022-4971?
To fix CVE-2022-4971, upgrade the Sassy Social Share plugin to version 3.3.4 or later.
What is affected by CVE-2022-4971?
CVE-2022-4971 affects the Sassy Social Share plugin for WordPress in versions up to and including 3.3.3.
What type of vulnerability is CVE-2022-4971?
CVE-2022-4971 is a reflected cross-site scripting (XSS) vulnerability.
When was CVE-2022-4971 disclosed?
CVE-2022-4971 was disclosed in 2022.