CVE-2025-5528

Social Sharing Plugin – Sassy Social Share <= 3.3.75 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action, such as clicking on a link.


We have discovered 28,158 live websites that are affected by CVE-2025-5528.

Run a Free Instant Scan




Affected Software

Product  Sassy Social Share
Category Wordpress Plugins
Vulnerable Domains28,158 live websites (100% of Sassy Social Share install base)
Vulnerable Versions
  • from 0 through 3.3.75
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 7, 2025
  • Updated - Jun 9, 2025

Credits

  • Naveen H N (finder)

Website Distribution by Country

Number of websites using CVE-2025-5528
United States9,903 websites



France1,762 websites
Italy1,693 websites
Germany1,592 websites
GB1,143 websites
Spain973 websites
India893 websites
Russia821 websites
Brazil599 websites
Netherlands569 websites

Website Distribution by TLD

Number of websites using CVE-2025-5528
.com12,684 websites
.ru1,771 websites
.org1,550 websites
.it1,228 websites
.net731 websites
.fr585 websites
.com.br524 websites
.co.uk479 websites
.de437 websites
.nl429 websites

Websites affected by CVE-2025-5528

Top websites that are affected by CVE-2025-5528. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.net Germany*,***
********.com United States*,***
******.com United States**,***
****************.com United States**,***
***************.org United States**,***
****************.org United States**,***
***.org United States**,***
**********.com United States**,***
*********.tv Germany**,***
****.pt Portugal**,***
See full domain list

FAQ

CVE-2025-5528 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Sassy Social Share
A total of 28,158 websites have been identified as vulnerable to CVE-2025-5528, based on global website indexing conducted by WebTechSurvey.
The Sassy Social Share is affected by the CVE-2025-5528 vulnerability.
Sassy Social Share versions up to and including 3.3.75 are vulnerable to CVE-2025-5528.