Sassy Social Share <=3.3.3 - Cross-Site Scripting
WordPress Sassy Social Share 3.3.3 and prior is vulnerable to cross-site scripting because certain AJAX endpoints return JSON data with no Content-Type header set and then use the default text/html. In other words, any JSON that has HTML will be rendered as such.
sassy_socialPoC 已收录
CVSS5.4