plugin

Kiwi Social Share Vulnerabilities

13 known security issues reported for the Kiwi Social Share WordPress plugin. Most recent disclosed Sep 5, 2025.

2 critical 2 medium

Running Kiwi Social Share on your site? Check whether your installed version is affected.

Scan your site free

Kiwi <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Kiwi plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will e...

CVSS:
6.4
Affected:
up to 2.1.8
Fix:
No patched version reported
Disclosed:
Sep 5, 2025

CVE-2025-58790 on NVD →

Social Sharing Plugin &#8211; Kiwi [kiwi-social-share] <= 2.1.8 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Kiwi allows Stored XSS. This issue affects Kiwi: from n/a through 2.1.8.

Affected:
up to 2.1.8
Fix:
No patched version reported
Disclosed:
Sep 5, 2025

CVE-2025-58790 on NVD →

Social Sharing Plugin &#8211; Kiwi [kiwi-social-share] < 2.1.8 (closed)

unknown

[en] The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' class. This makes it possible for unauthenticated attackers to view limited content from password protected posts.

Affected:
up to 2.1.8
Fixed in:
2.1.8
Disclosed:
Jul 9, 2024

CVE-2024-3228 on NVD →

Social Sharing Plugin – Kiwi <= 2.1.7 - Information Disclosure

medium

The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' class. This makes it possible for unauthenticated attackers to view limited content from password protected posts.

CVSS:
5.3
Affected:
up to 2.1.7
Fixed in:
2.1.8
Disclosed:
Jul 8, 2024

CVE-2024-3228 on NVD →

Social Sharing Plugin &#8211; Kiwi [kiwi-social-share] < 2.1.3 (closed)

unknown

[en] The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitra...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jun 7, 2023

CVE-2021-4362 on NVD →

Kiwi Social Sharing 2.1.0 - 2.1.2 - Arbitrary Options Change

critical

The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitrary op...

CVSS:
9.8
Affected:
2.1.0 – 2.1.2
Fixed in:
2.1.3
Disclosed:
Jun 4, 2021

CVE-2021-4362 on NVD →

Social Sharing Plugin &#8211; Kiwi [kiwi-social-share] < 2.1.3 (closed)

unknown

Unauthenticated WordPress Options Change/Read vulnerability discovered by NinTechNet in WordPress Kiwi Social Sharing plugin (versions <= 2.1.0).

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jun 4, 2021

Social Sharing Plugin &#8211; Kiwi [kiwi-social-share] < 2.1.3 (closed)

unknown

The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitrary op...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Jun 4, 2021

Social Sharing Plugin &#8211; Kiwi [kiwi-social-share] < 2.0.11 (closed)

unknown

Bypass (update any option) vulnerability found in WordPress Social Sharing Plugin – Kiwi plugin (versions <= 2.0.10).

Affected:
up to 2.0.11
Fixed in:
2.0.11
Disclosed:
Dec 7, 2018

Kiwi Social Share <= 2.0.10 - Arbitrary Options Update

critical

The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in versions up to, and including, 2.0.10. This makes it possible for unauthenticated attackers to read...

CVSS:
9.8
Affected:
up to 2.0.10
Fixed in:
2.0.11
Disclosed:
Nov 12, 2018

Social Sharing Plugin &#8211; Kiwi [kiwi-social-share] < 2.0.11 (closed)

unknown

The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in versions up to, and including, 2.0.10. This makes it possible for unauthenticated attackers to read...

Affected:
up to 2.0.11
Fixed in:
2.0.11
Disclosed:
Nov 12, 2018

Social Sharing Plugin &#8211; Kiwi [kiwi-social-share] < 2.1.3 (closed)

unknown

The plugin re-introduced an issue in v2.1.0, allowing unauthenticated attacker to update and read arbitrary WordPress options. This could allow them to create admin accounts by enabling registration and setting the user default role to administrator, or to modify the value of siteurl in order to redirect all traffic to...

Affected:
up to 2.1.3
Fixed in:
2.1.3

Social Sharing Plugin &#8211; Kiwi [kiwi-social-share] < 2.0.11 (closed)

unknown

The plugin allowed unauthenticated attackers to update and read arbitrary WordPress options.

Affected:
up to 2.0.11
Fixed in:
2.0.11

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database