S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24746 Scanner

CVE-2021-24746 scanner - Cross-Site Scripting (XSS) vulnerability in Social Sharing plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.1
CVSS
Description

The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Social Sharing Plugin – Sassy Social Share
AFFECTED< 3.3.40→SAFE ✓≥ 3.3.40
Updated Sep 22, 2026View on NVD →
Detail

The Social Sharing Plugin for WordPress is a popular tool used to help website owners increase their social media presence. It is a plugin that provides various social media sharing icons that can be integrated into blog posts or pages. Its main purpose is to make sharing website content on social media platforms easier and more accessible.

However, a vulnerability has been detected in the Social Sharing Plugin for WordPress, specifically the CVE-2021-24746 vulnerability. This vulnerability arises from the fact that this plugin fails to escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled. This results in a Reflected Cross-Site Scripting issue that can be exploited by hackers to inject malicious scripts into websites.

Exploitation of this vulnerability can lead to serious consequences, including the theft of sensitive data from users' computers or accounts, manipulation of user-generated content, and the takeover of the entire website. Hackers can use this vulnerability to execute code on users' computers that can compromise their security and privacy, leading to a wide range of cyber attacks such as phishing, malware, and ransomware.

It is essential to protect your website against vulnerabilities that can compromise your security and put your business at risk. With the pro features of the s4e.io platform, you can easily and quickly learn about vulnerabilities in your digital assets. The platform offers advanced vulnerability scanning and reporting tools that can help you identify and fix security issues before they can be exploited by hackers. By using s4e.io, you can take control of your website's security and protect your business from cyber threats.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-24746 vulnerability, website owners can take the following precautions:

  • Disable the "Enable 'More' icon" option in the Social Sharing Plugin for WordPress settings.
  • Update the Social Sharing Plugin for WordPress to the latest version as soon as an update is available.
  • Install a firewall that can monitor incoming traffic for malicious activity and block it if necessary.
  • Implement strong password policies and two-factor authentication to ensure that hackers cannot access website accounts.
  • Regularly scan the website for vulnerabilities or hire a security professional to conduct reviews and tests of the website's security posture.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.