Heateor develops a focused suite of WordPress social-media and engagement plugins—including Sassy Social Share, Super Socializer, Social Login, Fancy Comments, and Social Comments—that extend authentication, sharing, and commenting functionality across a modestly represented vendor portfolio. The recurring vulnerability surface spans input-handling and authentication weaknesses, most prominently cross-site scripting, SQL injection, improper authentication, and untrusted deserialization, reflecting the plugin ecosystem's exposure to both user-supplied data and third-party social-platform integrations. Public exploit code has acquired an elevated tendency to be developed for vulnerabilities in this vendor's plugins, likely driven by their wide deployment across WordPress sites and the relative ease of weaponizing web-application flaws at scale. Defenders should monitor Heateor's plugin releases closely and apply updates promptly, particularly for internet-facing WordPress installations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Heateor over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4971MEDIUM The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versi | Oct 16, 2024 | 6.1 | 35 | NO | YES |
CVE-2021-24987MEDIUM The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action | Apr 11, 2022 | 6.1 | 32 | NO | YES |
CVE-2021-24746MEDIUM The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is | Mar 28, 2022 | 6.1 | 31 | NO | YES |
CVE-2021-39321HIGH Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unva | Oct 21, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-10020HIGH The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verificatio | Nov 6, 2024 | 8.1 | 24 | NO | NO |
CVE-2024-9946HIGH The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13. | Nov 6, 2024 | 8.1 | 23 | NO | NO |
CVE-2022-4484MEDIUM The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back | Jan 16, 2023 | 5.4 | 21 | NO | NO |
CVE-2023-23977MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments plugin <= 1.6.1 ver | Apr 4, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-23670MEDIUM Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions. | Mar 30, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-4451MEDIUM The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users wit | Jan 16, 2023 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Heateor.
Media articles that mention a CVE ID that affects a product developed by Heateor — matched by CVE ID, not by vendor name.