Easy Social Share Buttons < 10.7.1 - Unauthenticated Stored Cross-Site Scripting
high
The Easy Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 10.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 10.7.1
- Fixed in:
- 10.7.1
- Disclosed:
- Oct 26, 2025
CVE-2025-64198 on NVD →
Easy Social Share Buttons [easy-social-share-buttons3] < 9.5
unknown
[en] Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: from n/a through 9.4.
- Affected:
- up to 9.5
- Fixed in:
- 9.5
- Disclosed:
- Jun 9, 2024
CVE-2024-31307 on NVD →
Easy Social Share Buttons [easy-social-share-buttons3] < 9.5
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4.
- Affected:
- up to 9.5
- Fixed in:
- 9.5
- Disclosed:
- May 17, 2024
CVE-2024-31300 on NVD →
Easy Social Share Buttons <= 9.4 - Authenticated (Subscriber+) Local File Inclusion
high
The Easy Social Share Buttons for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of an...
- CVSS:
- 8.8
- Affected:
- up to 9.4
- Fixed in:
- 9.5
- Disclosed:
- Apr 5, 2024
CVE-2024-31300 on NVD →
Easy Social Share Buttons <= 9.4 - Missing Authorization
medium
The Easy Social Share Buttons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 9.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 9.4
- Fixed in:
- 9.5
- Disclosed:
- Apr 5, 2024
CVE-2024-31307 on NVD →
Easy Social Share Buttons <= 9.4 - Reflected Cross-Site Scripting
medium
The easy-social-share-buttons3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 9.4
- Fixed in:
- 9.5
- Disclosed:
- Mar 25, 2024
CVE-2024-30196 on NVD →
Easy Social Share Buttons [easy-social-share-buttons3] < 10.7.1
unknown
- Affected:
- up to 10.7.1
- Fixed in:
- 10.7.1
CVE-2025-64198 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database