CVE Feed

    Dashboard / CVE / CVE-2021-39321

    CVE-2021-39321

    Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file. This can be exploited by underprivileged authenticated users due to a missing capability check on the import_config function.

    Published:Oct 21, 2021
    Last Modified:Mar 31, 2025
    EPS:Oct 21, 2021
    EPSS Score:0.01146
    CVSS Score:8.8

    Affected Products

    Vendor
    Heateor
    Product
    Sassy Social Share

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High