The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
We have discovered 9,157 live websites that are affected by CVE-2022-4451.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 9,157 live websites (19.20% of Sassy Social Share install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 95 versions ( 76.61% of all versions) |
![]() | 3,755 websites |
![]() | 662 websites |
![]() | 613 websites |
![]() | 410 websites |
![]() | 321 websites |
![]() | 273 websites |
![]() | 255 websites |
![]() | 171 websites |
![]() | 146 websites |
![]() | 145 websites |
.com | 4,055 websites |
.ru | 799 websites |
.org | 458 websites |
.it | 266 websites |
.net | 207 websites |
.com.br | 204 websites |
.fr | 186 websites |
.de | 145 websites |
.es | 138 websites |
.com.au | 130 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
*********.pl | ![]() | **,*** | |
****.************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
********.com | ![]() | ***,*** | |
*****.**.edu | ![]() | ***,*** | |
**********.es | ![]() | ***,*** | |
*******.***********.com | ![]() | ***,*** | |
*********.com | ![]() | ***,*** |
FAQ