WordPress · Super Socializer · CVE-2026-11798
**Name of the Vulnerable Software and Affected Versions**
Super Socializer versions prior to 7.14.6
**Description**
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting. This occurs when an attacker tricks a user into clicking a link containing a malicious script injected via the `heateor mastodon share` parameter.
**Recommendations**
Update to version 7.14.6 or later.
Avoid using the `heateor mastodon share` parameter until the update is applied.