The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-03-28T17:20:47
Updated: 2024-08-03T19:42:16.645Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24746
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-03-28T18:15:08.313
Modified: 2022-04-04T16:03:19.840
Link: CVE-2021-24746
Redhat
No data.