Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Phishing.This issue affects Sassy Social Share: from n/a through <= 3.3.73.
Published: 2025-04-24
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Sassy Social Share plugin contains an open redirect flaw that allows an attacker to supply a crafted URL that redirects users to an arbitrary external site. This vulnerability can be leveraged to trick users into clicking links that appear legitimate but lead to malicious domains, facilitating phishing attacks and credential compromise. The weakness is classified as an uncontrolled redirection (CWE‑601).

Affected Systems

WordPress sites running the Heateor Support Sassy Social Share plugin version 3.3.73 or older are vulnerable. The affected product is the Sassy Social Share plugin distributed by Heateor Support.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of public exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying it has not been confirmed as actively exploited. The likely attack vector is an external user visiting a malicious link that includes the vulnerable plugin’s redirect mechanism, enabling attackers to manipulate end‑user navigation with minimal prerequisites.

Generated by OpenCVE AI on May 1, 2026 at 09:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Sassy Social Share plugin to the latest version that removes the open redirect flaw (3.3.74 or newer).
  • Review the plugin’s redirect settings and restrict them to a whitelist of trusted domains.
  • Check for any plugin updates or patches via the Heateor Support website or within the WordPress admin updates page.

Generated by OpenCVE AI on May 1, 2026 at 09:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12065 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share allows Phishing. This issue affects Sassy Social Share: from n/a through 3.3.73.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share allows Phishing. This issue affects Sassy Social Share: from n/a through 3.3.73. URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Phishing.This issue affects Sassy Social Share: from n/a through <= 3.3.73.
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Fri, 25 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share allows Phishing. This issue affects Sassy Social Share: from n/a through 3.3.73.
Title WordPress Sassy Social Share plugin <= 3.3.73 - Open Redirection vulnerability
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:30.280Z

Reserved: 2025-04-16T06:22:51.799Z

Link: CVE-2025-39404

cve-icon Vulnrichment

Updated: 2025-04-24T19:56:13.500Z

cve-icon NVD

Status : Deferred

Published: 2025-04-24T16:15:33.010

Modified: 2026-04-23T15:29:29.413

Link: CVE-2025-39404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:15:13Z

Weaknesses