Impact
The Sassy Social Share plugin contains an open redirect flaw that allows an attacker to supply a crafted URL that redirects users to an arbitrary external site. This vulnerability can be leveraged to trick users into clicking links that appear legitimate but lead to malicious domains, facilitating phishing attacks and credential compromise. The weakness is classified as an uncontrolled redirection (CWE‑601).
Affected Systems
WordPress sites running the Heateor Support Sassy Social Share plugin version 3.3.73 or older are vulnerable. The affected product is the Sassy Social Share plugin distributed by Heateor Support.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of public exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying it has not been confirmed as actively exploited. The likely attack vector is an external user visiting a malicious link that includes the vulnerable plugin’s redirect mechanism, enabling attackers to manipulate end‑user navigation with minimal prerequisites.
OpenCVE Enrichment
EUVD