Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-2159 2 Heateor, Wpsocialrocket 2 Sassy Social Share, Social Sharing Plugin 2025-05-08 4.7 Medium
The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2020-5611 1 Wpsocialrocket 1 Social Sharing 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors.