plugin

Easy Social Share Buttons3 Vulnerabilities

7 known security issues reported for the Easy Social Share Buttons3 WordPress plugin. Most recent disclosed Oct 26, 2025.

2 high 2 medium

Running Easy Social Share Buttons3 on your site? Check whether your installed version is affected.

Scan your site free

Easy Social Share Buttons < 10.7.1 - Unauthenticated Stored Cross-Site Scripting

high

The Easy Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 10.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 10.7.1
Fixed in:
10.7.1
Disclosed:
Oct 26, 2025

CVE-2025-64198 on NVD →

Easy Social Share Buttons [easy-social-share-buttons3] < 9.5

unknown

[en] Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: from n/a through 9.4.

Affected:
up to 9.5
Fixed in:
9.5
Disclosed:
Jun 9, 2024

CVE-2024-31307 on NVD →

Easy Social Share Buttons [easy-social-share-buttons3] < 9.5

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4.

Affected:
up to 9.5
Fixed in:
9.5
Disclosed:
May 17, 2024

CVE-2024-31300 on NVD →

Easy Social Share Buttons <= 9.4 - Authenticated (Subscriber+) Local File Inclusion

high

The Easy Social Share Buttons for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of an...

CVSS:
8.8
Affected:
up to 9.4
Fixed in:
9.5
Disclosed:
Apr 5, 2024

CVE-2024-31300 on NVD →

Easy Social Share Buttons <= 9.4 - Missing Authorization

medium

The Easy Social Share Buttons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 9.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 9.4
Fixed in:
9.5
Disclosed:
Apr 5, 2024

CVE-2024-31307 on NVD →

Easy Social Share Buttons <= 9.4 - Reflected Cross-Site Scripting

medium

The easy-social-share-buttons3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 9.4
Fixed in:
9.5
Disclosed:
Mar 25, 2024

CVE-2024-30196 on NVD →

Easy Social Share Buttons [easy-social-share-buttons3] < 10.7.1

unknown
Affected:
up to 10.7.1
Fixed in:
10.7.1

CVE-2025-64198 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database