CVE-2026-94170: WordPress Sassy Social Share plugin <= 3.3.79 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Reflected XSS.This issue affects Sassy Social Share: from n/a through 3.3.79.
Affected Software
Event History
Frequently Asked Questions
Which plugin versions are affected?
Sassy Social Share versions through 3.3.79 are affected. The available data does not identify the first affected version.
What does an attacker need to exploit this issue?
The vulnerability is network-accessible and requires no attacker privileges, but it does require user interaction. It is a reflected XSS issue, meaning exploitation depends on getting a user to load attacker-influenced web content.
What impact can successful exploitation have?
Successful exploitation can affect confidentiality, integrity, and availability at low impact levels, with impacts extending beyond the vulnerable component's security authority.