Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sassy Social Share MEDIUM 6.1
CVE-2025-5528

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share pa…

Fix: 3.3.76+
Fix from $1,600 2025-06-07
Super Socializer MEDIUM 5.3
CVE-2024-13230

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘Sup…

Fix: 7.14.1+
Fix from $1,600 2025-01-21
Sassy Social Share MEDIUM 6.1
CVE-2024-11252

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share pa…

Fix: 3.3.70+
Fix from $1,600 2024-11-30
Super Socializer HIGH 8.1
CVE-2024-9946

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versi…

Fix: 7.14+
Fix from $1,950 2024-11-06
Social Login HIGH 8.1
CVE-2024-10020

The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is …

Fix: 1.1.36+
Fix from $1,950 2024-11-06
Sassy Social Share MEDIUM 6.1
CVE-2022-4971EPSS 16%

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_shar…

Fix: after 3.3.3
Fix from $1,600 2024-10-16
Sassy Social Share MEDIUM 6.1
CVE-2024-4924

The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users s…

Fix: 3.6.3+
Fix from $1,600 2024-06-12
Social Login MEDIUM 6.1
CVE-2024-35706

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows…

Fix: 1.1.33+
Fix from $1,600 2024-06-08
Social Login MEDIUM 5.4
CVE-2024-35707

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows…

Fix: 1.1.33+
Fix from $1,600 2024-06-08
Social Login MEDIUM 5.4
CVE-2024-32674

Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script…

Fix: 1.1.32+
Fix from $1,600 2024-05-08
Fancy Comments MEDIUM 5.4
CVE-2024-29804

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows St…

Fix: after 1.2.14
Fix from $1,600 2024-03-27
Sassy Social Share MEDIUM 5.4
CVE-2024-1989

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share…

Fix: 3.3.59+
Fix from $1,600 2024-03-06
Sassy Social Share MEDIUM 6.4
CVE-2024-1448

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all…

Fix: after 3.3.56
Fix from $1,600 2024-02-29
Social Login MEDIUM 5.4
CVE-2024-24712

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress all…

Fix: 1.1.31+
Fix from $1,600 2024-02-10
Super Socializer MEDIUM 5.4
CVE-2023-35882

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 versions.

Fix: after 7.13.52
Fix from $1,600 2023-06-20
Social Comments MEDIUM 5.4
CVE-2023-23977

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disq…

Fix: 1.6.2+
Fix from $1,600 2023-04-04
Fancy Comments MEDIUM 5.4
CVE-2023-23670

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions.

Fix: 1.2.11+
Fix from $1,600 2023-03-30
Super Socializer MEDIUM 5.4
CVE-2022-4484

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attribut…

Fix: 7.13.44+
Fix from $1,600 2023-01-16
Sassy Social Share MEDIUM 5.4
CVE-2022-4451

The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the pa…

Fix: 3.3.45+
Fix from $1,600 2023-01-16
Super Socializer MEDIUM 6.1
CVE-2021-24987

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_…

Fix: 7.13.30+
Fix from $1,600 2022-04-11
Sassy Social Share MEDIUM 6.1
CVE-2021-24746

The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the…

Fix: 3.3.40+
Fix from $1,600 2022-03-28
Sassy Social Share HIGH 8.8
CVE-2021-39321

Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action…

Patch available
Fix from $1,950 2021-10-21