CVE-2024-11252

Social Sharing Plugin – Sassy Social Share <= 3.3.69 - Reflected Cross-Site Scripting via heateor_mastodon_share Parameter

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.


We have discovered 16,735 live websites that are affected by CVE-2024-11252.

Run a Free Instant Scan




Affected Software

Product  Sassy Social Share
Category Wordpress Plugins
Vulnerable Domains16,735 live websites (100% of Sassy Social Share install base)
Vulnerable Versions
  • from 0 through 3.3.69
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 30, 2024
  • Updated - Dec 1, 2024

Credits

  • Michael Mazzolini (finder)

Website Distribution by Country

Number of websites using CVE-2024-11252
United States5,757 websites



France1,047 websites
Italy1,001 websites
Germany920 websites
GB658 websites
Russia656 websites
India567 websites
Spain555 websites
Brazil377 websites
Poland286 websites

Website Distribution by TLD

Number of websites using CVE-2024-11252
.com7,410 websites
.ru1,243 websites
.org890 websites
.it734 websites
.net431 websites
.fr335 websites
.com.br335 websites
.co.uk265 websites
.de250 websites
.es222 websites

Websites affected by CVE-2024-11252

Top websites that are affected by CVE-2024-11252. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States**,***
****************.com United States**,***
***************.org United States**,***
**********.com United States**,***
*****.app Bulgaria**,***
***.***.br Brazil**,***
*************.com United States**,***
*******.com United States**,***
***.**.th Thailand**,***
*********.org United States**,***
See full domain list

FAQ

CVE-2024-11252 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Sassy Social Share
A total of 16,735 websites have been identified as vulnerable to CVE-2024-11252, based on global website indexing conducted by WebTechSurvey.
The Sassy Social Share is affected by the CVE-2024-11252 vulnerability.
Sassy Social Share versions up to and including 3.3.69 are vulnerable to CVE-2024-11252.