CVE-2024-1448
Heateor
CVE-2024-1448 is a Stored Cross-Site Scripting (XSS) vulnerability in the Sassy Social Share WordPress plugin. This flaw allows authenticated attackers with contributor or higher permissions to inject malicious web scripts into WordPress pages. The injected scripts execute whenever a user visits the compromised page, potentially leading to session hijacking, data theft, or defacement.
Specifically, versions of the plugin up to and including 3.3.56 lack proper input sanitization and output escaping for user-supplied attributes in the plugin's shortcodes. Despite the low SVRS score of 30, indicating less immediate threat activity based on vulnerability intelligence, the CWE-79 vulnerability type is still significant. Successful exploitation could compromise user accounts and the integrity of the WordPress website. While CVSS score is zero and the SVRS may suggest lower risk, administrators should still patch due to potential for exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.