Sceawere

Vulnerability Detail

CVE-2026-94170UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in Sassy Social Share

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Heateor Support
Product
Sassy Social Share
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Reflected XSS.This issue affects Sassy Social Share: from n/a through 3.3.79.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-09T10:16:40.333Z",
  "pubdate": "2026-10-09T10:16:40.333Z",
  "executiveSummary": "Sassy Social Share is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability, classified under CWE-79: Improper Neutralization of Input During Web Page Generation.\nThis vulnerability allows an unauthenticated, remote attacker to inject malicious scripts into the user's browser session by manipulating input parameters handled by the plugin.\nAffected versions range from n/a through 3.3.79.\nSuccessful exploitation results in the execution of arbitrary JavaScript within the context of the victim's session, potentially leading to unauthorized actions, session hijacking, or the exfiltration of sensitive cookies and data.\nThe risk is considered significant as it requires only that an authenticated or unauthenticated user be coerced into clicking a specially crafted URL, bypassing typical security perimeters without requiring administrative privileges.",
  "technicalDetails": "The vulnerability resides in the way the Sassy Social Share plugin processes user-supplied input before rendering it in the generated HTML output. The root cause is the failure to properly sanitize or neutralize input parameters before they are reflected back to the client side, violating core secure coding principles for web applications.\nIn a Reflected XSS scenario, the attack flow begins with an attacker crafting a malicious URL containing a payload—typically a script tag or event handler—within a vulnerable parameter recognized by the plugin. The attacker then distributes this URL to a victim, often through phishing, social engineering, or redirection techniques.\nWhen the victim executes the link, the server receives the malicious request and reflects the unsanitized input directly into the HTML response document. The user's browser, receiving the malformed page, interprets the malicious payload as legitimate content originating from the trusted domain. Because the script executes within the victim's origin, it inherits the application's permissions, granting the attacker access to the browser's Document Object Model (DOM), session storage, and local storage.\nThe impact of this payload execution is extensive. An attacker can perform actions on behalf of the user, such as modifying plugin configurations, posting content, or escalating privileges if the victim is an administrator. Furthermore, the attacker can leverage the XSS to perform credential theft via keylogging or by intercepting session tokens and transmitting them to a remote server under the attacker's control.\nExploitation is not contingent upon specific server-side authentication, as the 'reflected' nature of the vulnerability relies on the interaction between the application's input processing logic and the client's rendering engine. The lack of proper output encoding or input validation allows the injection of executable code into the web page context, exposing all users of the plugin to potential compromise regardless of their role within the WordPress environment."
}
CVE-2026-94170: Reflected XSS in Sassy Social Share (HIGH Severity, CVSS: 7.1) | Sceawere