Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
medium
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 2.07
- Fixed in:
- 2.08
- Disclosed:
- Apr 30, 2026
CVE-2024-13362 on NVD →
Share This Image <= 2.12 - Missing Authorization
medium
The Share This Image plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.12. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.12
- Fixed in:
- 2.13
- Disclosed:
- Mar 26, 2026
CVE-2026-39563 on NVD →
Share This Image <= 2.14 - Unauthenticated Server-Side Request Forgery
high
The Share This Image plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from...
- CVSS:
- 7.2
- Affected:
- up to 2.14
- Fixed in:
- 2.15
- Disclosed:
- Feb 13, 2026
CVE-2026-42641 on NVD →
Share This Image [share-this-image] <= 2.09 (unfixed)
unknown
[en] Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.09.
- Affected:
- up to 2.09
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-25010 on NVD →
Share This Image <= 2.09 - Missing Authorization
medium
The Share This Image plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.09. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.09
- Fixed in:
- 2.10
- Disclosed:
- Jan 25, 2026
CVE-2026-25010 on NVD →
Share This Image [share-this-image] < 1.67
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 1.67
- Fixed in:
- 1.67
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
Share This Image [share-this-image] < 2.02
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ILLID Share This Image allows Reflected XSS.This issue affects Share This Image: from n/a through 2.01.
- Affected:
- up to 2.02
- Fixed in:
- 2.02
- Disclosed:
- Oct 6, 2024
CVE-2024-47326 on NVD →
Share This Image <= 2.01 - Reflected Cross-Site Scripting
medium
The Share This Image plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 2.01
- Fixed in:
- 2.02
- Disclosed:
- Sep 25, 2024
CVE-2024-47326 on NVD →
Share This Image [share-this-image] < 2.04
unknown
[en] The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if t...
- Affected:
- up to 2.04
- Fixed in:
- 2.04
- Disclosed:
- Sep 17, 2024
CVE-2024-8761 on NVD →
Share This Image <= 2.03 - Open Redirect via link Parameter
high
The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they c...
- CVSS:
- 7.2
- Affected:
- up to 2.03
- Fixed in:
- 2.04
- Disclosed:
- Sep 16, 2024
CVE-2024-8761 on NVD →
Share This Image [share-this-image] < 2.03
unknown
[en] The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and including, 2.02 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...
- Affected:
- up to 2.03
- Fixed in:
- 2.03
- Disclosed:
- Sep 5, 2024
CVE-2024-8363 on NVD →
Share This Image <= 2.02 - Authenticated (Contributor+) Stored Cross-Site Scripting via STI Buttons Shortcode
medium
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and including, 2.02 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...
- CVSS:
- 6.4
- Affected:
- up to 2.02
- Fixed in:
- 2.03
- Disclosed:
- Sep 4, 2024
CVE-2024-8363 on NVD →
Share This Image [share-this-image] < 2.02
unknown
[en] The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to...
- Affected:
- up to 2.02
- Fixed in:
- 2.02
- Disclosed:
- Aug 31, 2024
CVE-2024-8108 on NVD →
Share This Image <= 2.01 - Authenticated (Contributor+) Stored Cross-Site Scripting via alignment Parameter
medium
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inje...
- CVSS:
- 6.4
- Affected:
- up to 2.01
- Fixed in:
- 2.02
- Disclosed:
- Aug 30, 2024
CVE-2024-8108 on NVD →
Share This Image [share-this-image] < 1.99
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ILLID Share This Image.This issue affects Share This Image: from n/a through 1.97.
- Affected:
- up to 1.99
- Fixed in:
- 1.99
- Disclosed:
- May 2, 2024
CVE-2024-33930 on NVD →
Share This Image <= 1.98 - Open Redirect
medium
The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.98. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick the...
- CVSS:
- 5.4
- Affected:
- up to 1.98
- Fixed in:
- 1.99
- Disclosed:
- Apr 29, 2024
CVE-2024-33930 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 1.47 – 1.80
- Fixed in:
- 1.81
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.67
- Fixed in:
- 1.67
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Share This Image [share-this-image] < 1.67
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 1.67
- Fixed in:
- 1.67
- Disclosed:
- Mar 4, 2022
Share This Image [share-this-image] < 1.67
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress Share This Image plugin (versions <= 1.66).
- Affected:
- up to 1.67
- Fixed in:
- 1.67
- Disclosed:
- Feb 28, 2022
Share This Image [share-this-image] < 1.67
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Share This Image plugin (versions <= 1.66).
- Affected:
- up to 1.67
- Fixed in:
- 1.67
- Disclosed:
- Feb 28, 2022
Share This Image [share-this-image] < 1.04
unknown
[en] The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter.
- Affected:
- up to 1.04
- Fixed in:
- 1.04
- Disclosed:
- Jan 2, 2018
CVE-2017-18015 on NVD →
Share This Image < 1.04 - Cross-Site Scripting
medium
The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.04
- Fixed in:
- 1.04
- Disclosed:
- Dec 18, 2017
CVE-2017-18015 on NVD →
Share This Image [share-this-image] < 1.20
unknown
Stored XSS occurs when a web application gathers input from a user which might be malicious, and then stores that input in a data store for later use. The input that is stored is not correctly filtered
- Affected:
- up to 1.20
- Fixed in:
- 1.20
Share This Image [share-this-image] < 1.81
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.81
- Fixed in:
- 1.81
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database