Heateor
Heateor Super Socializer: vulnerabilidades y CVE
Heateor Super Socializer tiene 10 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65544 | Alta (7.1) | 0.25% | — | 6 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. |
| CVE-2026-65542 | Alta (8.8) | 0.50% | — | 6 ago 2026 | Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. |
| CVE-2026-11798 | Media (6.1) | 0.36% | — | 8 jul 2026 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and… |
| CVE-2024-13230 | Media (5.3) | 0.44% | — | 21 ene 2025 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter in all versions up to, and including, 7.14… |
| CVE-2023-41802 | Media (4.3) | 0.73% | — | 13 dic 2024 | Missing Authorization vulnerability in Team Heateor Super Socializer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Socializer: from n/a through 7.13.54. |
| CVE-2024-9946 | Alta (8.1) | 0.63% | — | 6 nov 2024 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient… |
| CVE-2024-2836 | Media (4.8) | 0.50% | — | 15 abr 2024 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site… |
| CVE-2023-35882 | Media (5.4) | 0.42% | — | 20 jun 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 versions. |
| CVE-2022-4484 | Media (5.4) | 0.47% | — | 16 ene 2023 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users… |
| CVE-2021-24987 | Media (6.1) | 1.9% | — | 11 abr 2022 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.