Impact
The plugin accepts the heateor_mastodon_share parameter without proper sanitisation or escaping, allowing attackers to embed arbitrary JavaScript into HTTP responses. When a victim follows a crafted link or submits a form containing a malicious value for this parameter, the script executes in their browser. This reflected Cross‑Site Scripting can be used to steal session cookies, deface content, or redirect users to phishing sites, thereby compromising confidentiality and integrity of the site and its users.
Affected Systems
Any WordPress installation that has the Super Socializer plugin – Social Share, Social Login and Social Comments Plugin – Super Socializer by the_champ with a version of 7.14.5 or earlier is affected. The vulnerability exists in all those releases up to and including 7.14.5.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity vulnerability. The EPSS score is less than 1% and the flaw is not listed in the CISA KEV catalog. Exploitation requires no authentication; an attacker merely crafts a URL or link that includes a malicious heateor_mastodon_share value and lures a user to click it. Success depends on social engineering, and the impact is limited to the victim’s browser session.
OpenCVE Enrichment