The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
We have discovered 15,939 live websites that are affected by CVE-2024-2159.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 15,939 live websites (33.41% of Sassy Social Share install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 111 versions ( 89.52% of all versions) |
![]() | 6,488 websites |
![]() | 1,170 websites |
![]() | 1,140 websites |
![]() | 562 websites |
![]() | 524 websites |
![]() | 503 websites |
![]() | 493 websites |
![]() | 297 websites |
![]() | 270 websites |
![]() | 264 websites |
.com | 7,411 websites |
.ru | 919 websites |
.org | 833 websites |
.it | 452 websites |
.net | 438 websites |
.com.br | 344 websites |
.fr | 322 websites |
.es | 240 websites |
.de | 238 websites |
.co.uk | 230 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*****.app | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
*********.pl | ![]() | **,*** | |
******.com | ![]() | **,*** | |
*****************.com | ![]() | **,*** | |
****.************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
**************.com | ![]() | **,*** |
FAQ