CVE-2025-39404: WordPress Sassy Social Share plugin <= 3.3.73 - Open Redirection vulnerability
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share allows Phishing. This issue affects Sassy Social Share: from n/a through 3.3.73.
Other sources
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Phishing.This issue affects Sassy Social Share: from n/a through <= 3.3.73.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39404?
CVE-2025-39404 is classified as a moderate severity vulnerability due to its potential for enabling phishing attacks through open redirection.
How do I fix CVE-2025-39404?
To fix CVE-2025-39404, update the Heateor Sassy Social Share plugin to the latest version beyond 3.3.73.
What types of attacks can CVE-2025-39404 facilitate?
CVE-2025-39404 can facilitate phishing attacks by redirecting users to untrusted sites.
Which versions of Sassy Social Share are affected by CVE-2025-39404?
CVE-2025-39404 affects all versions of the Sassy Social Share plugin up to and including version 3.3.73.
Is CVE-2025-39404 specific to any content management system?
Yes, CVE-2025-39404 specifically affects the Heateor Sassy Social Share plugin used with WordPress.