CVE-2025-39404

WordPress Sassy Social Share plugin <= 3.3.73 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Heateor Support Sassy Social Share allows Phishing. This issue affects Sassy Social Share: from n/a through 3.3.73.


We have discovered 22,777 live websites that are affected by CVE-2025-39404.

Run a Free Instant Scan




Affected Software

Product  Sassy Social Share
Category Wordpress Plugins
Vulnerable Domains22,777 live websites (100% of Sassy Social Share install base)
Vulnerable Versions
  • from 0 through 3.3.73
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')



Details

  • Published - Apr 24, 2025
  • Updated - Apr 25, 2025

Credits

  • Affan Ali - @MuslimFromPK (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-39404
United States7,740 websites



France1,454 websites
Italy1,427 websites
Germany1,305 websites
GB876 websites
Spain788 websites
Russia759 websites
India747 websites
Brazil511 websites
Netherlands411 websites

Website Distribution by TLD

Number of websites using CVE-2025-39404
.com10,274 websites
.ru1,338 websites
.org1,227 websites
.it1,044 websites
.net592 websites
.fr480 websites
.com.br442 websites
.de361 websites
.co.uk356 websites
.es312 websites

Websites affected by CVE-2025-39404

Top websites that are affected by CVE-2025-39404. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
******.com United States**,***
****************.com United States**,***
***************.org United States**,***
**********.com United States**,***
****.pt Portugal**,***
*****************.com United States**,***
*****.app Bulgaria**,***
***.***.br Brazil**,***
**********.com United States**,***
See full domain list

FAQ

CVE-2025-39404 is URL Redirection to Untrusted Site ('Open Redirect') in Sassy Social Share
A total of 22,777 websites have been identified as vulnerable to CVE-2025-39404, based on global website indexing conducted by WebTechSurvey.
The Sassy Social Share is affected by the CVE-2025-39404 vulnerability.
Sassy Social Share versions up to and including 3.3.73 are vulnerable to CVE-2025-39404.