CVE-2024-4924: Sassy social share < 3.3.63 Admin+ Stored Cross-Site scripting
The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4924?
The severity of CVE-2024-4924 is categorized as high due to its potential for allowing Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-4924?
To fix CVE-2024-4924, update the Social Sharing Plugin to version 3.3.63 or later.
Who is affected by CVE-2024-4924?
CVE-2024-4924 affects users of the Social Sharing Plugin for WordPress prior to version 3.3.63.
What type of attacks can be executed due to CVE-2024-4924?
CVE-2024-4924 allows high privilege users to perform Stored Cross-Site Scripting attacks.
Is there a workaround for CVE-2024-4924 if I cannot update immediately?
While the best action is to update, a temporary workaround involves disabling the Social Sharing Plugin until the update is applied.