Sceawere
Vulnerability Detail
CVE-2026-94170UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in Sassy Social Share
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Heateor Support
- Product
- Sassy Social Share
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Reflected XSS.This issue affects Sassy Social Share: from n/a through 3.3.79.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:40.333Z",
"pubdate": "2026-10-09T10:16:40.333Z",
"executiveSummary": "Sassy Social Share is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability, classified under CWE-79: Improper Neutralization of Input During Web Page Generation.\nThis vulnerability allows an unauthenticated, remote attacker to inject malicious scripts into the user's browser session by manipulating input parameters handled by the plugin.\nAffected versions range from n/a through 3.3.79.\nSuccessful exploitation results in the execution of arbitrary JavaScript within the context of the victim's session, potentially leading to unauthorized actions, session hijacking, or the exfiltration of sensitive cookies and data.\nThe risk is considered significant as it requires only that an authenticated or unauthenticated user be coerced into clicking a specially crafted URL, bypassing typical security perimeters without requiring administrative privileges.",
"technicalDetails": "The vulnerability resides in the way the Sassy Social Share plugin processes user-supplied input before rendering it in the generated HTML output. The root cause is the failure to properly sanitize or neutralize input parameters before they are reflected back to the client side, violating core secure coding principles for web applications.\nIn a Reflected XSS scenario, the attack flow begins with an attacker crafting a malicious URL containing a payload—typically a script tag or event handler—within a vulnerable parameter recognized by the plugin. The attacker then distributes this URL to a victim, often through phishing, social engineering, or redirection techniques.\nWhen the victim executes the link, the server receives the malicious request and reflects the unsanitized input directly into the HTML response document. The user's browser, receiving the malformed page, interprets the malicious payload as legitimate content originating from the trusted domain. Because the script executes within the victim's origin, it inherits the application's permissions, granting the attacker access to the browser's Document Object Model (DOM), session storage, and local storage.\nThe impact of this payload execution is extensive. An attacker can perform actions on behalf of the user, such as modifying plugin configurations, posting content, or escalating privileges if the victim is an administrator. Furthermore, the attacker can leverage the XSS to perform credential theft via keylogging or by intercepting session tokens and transmitting them to a remote server under the attacker's control.\nExploitation is not contingent upon specific server-side authentication, as the 'reflected' nature of the vulnerability relies on the interaction between the application's input processing logic and the client's rendering engine. The lack of proper output encoding or input validation allows the injection of executable code into the web page context, exposing all users of the plugin to potential compromise regardless of their role within the WordPress environment."
}