plugin

Simple Social Buttons Vulnerabilities

21 known security issues reported for the Simple Social Buttons WordPress plugin. Most recent disclosed Apr 7, 2026.

8 medium

Running Simple Social Buttons on your site? Check whether your installed version is affected.

Scan your site free

Simple Social Media Share Buttons – Social Sharing for Everyone <= 6.2.0 - Cross-Site Request Forgery

medium

The Simple Social Media Share Buttons – Social Sharing for Everyone plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unautho...

CVSS:
4.3
Affected:
up to 6.2.0
Fixed in:
6.2.1
Disclosed:
Apr 7, 2026

CVE-2026-34904 on NVD →

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 6.0.0

unknown

[en] The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 6.0.0
Fixed in:
6.0.0
Disclosed:
Apr 15, 2025

CVE-2024-13610 on NVD →

Simple Social Media Share Buttons <= 5.4.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary w...

CVSS:
4.4
Affected:
up to 5.4.0
Fixed in:
6.0.0
Disclosed:
Mar 25, 2025

CVE-2024-13610 on NVD →

Simple Social Media Share Buttons <= 5.1.0 - Unauthenticated Password Protected Post Disclosure

medium

The Simple Social Media Share Buttons – Social Sharing for Everyone plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.0 via meta tags. This makes it possible for unauthenticated attackers to retrieve data from password protected posts that may have sensitive...

CVSS:
5.3
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Dec 6, 2023

CVE-2023-5845 on NVD →

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 5.1.1

unknown

[en] The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta tags

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Nov 27, 2023

CVE-2023-5845 on NVD →

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 3.2.4

unknown

[en] The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disall...

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Oct 11, 2021

CVE-2021-24656 on NVD →

Simple Social Media Share Buttons <= 3.2.3 - Admin+ Stored Cross-Site Scripting

medium

The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
4.8
Affected:
up to 3.2.3
Fixed in:
3.2.4
Disclosed:
Sep 13, 2021

CVE-2021-24656 on NVD →

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 3.2.3

unknown

[en] The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Aug 23, 2021

CVE-2021-24486 on NVD →

Simple Social Media Share Buttons <= 3.2.2 - Contributor+ Stored Cross-Site Scripting

medium

The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

CVSS:
5.4
Affected:
up to 3.2.2
Fixed in:
3.2.3
Disclosed:
Jul 26, 2021

CVE-2021-24486 on NVD →

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 3.2.1

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in WordPress Simple Social Media Share Buttons plugin (versions <= 3.2.0).

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Dec 19, 2020

Simple Social Media Share Buttons <= 3.2.0 - Reflected Cross-Site Scripting

medium

The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'share_counts' parameter in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

CVSS:
6.1
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Dec 18, 2020

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 3.2.0

unknown

Reflected Cross-Site Scripting (XSS) vulnerability found by Mr.F in WordPress Simple Social Media Share Buttons plugin (versions <= 3.1.1).

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Dec 18, 2020

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 3.2.1

unknown

The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'share_counts' parameter in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Dec 18, 2020

Simple Social Media Share Buttons <= 3.1.1 - Reflected Cross-Site Scripting

medium

The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...

CVSS:
6.1
Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Dec 17, 2020

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 3.2.0

unknown

The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Dec 17, 2020

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] >= 2.0.4 - <= 2.0.21

unknown

Authenticated Option Injection vulnerability found by Luka Šikić in WordPress Simple Social Media Share Buttons plugin (versions 2.0.4-2.0.21).

Affected:
2.0.4 – 2.0.21
Fixed in:
2.0.21
Disclosed:
Feb 12, 2019

Simple Social Media Share Buttons 2.0.4 - 2.0.21 - Missing Authorization

medium

The Simple Social Media Share Buttons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the download(), import(), and download_help() functions in versions 2.0.4 - 2.0.21. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to...

CVSS:
6.3
Affected:
2.0.4 – 2.0.21
Fixed in:
2.0.22
Disclosed:
Feb 11, 2019

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] >= 2.0.4 - <= 2.0.21

unknown

The Simple Social Media Share Buttons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the download(), import(), and download_help() functions in versions 2.0.4 - 2.0.21. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to...

Affected:
2.0.4 – 2.0.21
Fixed in:
2.0.21
Disclosed:
Feb 11, 2019

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 3.2.0

unknown

Simple Social Buttons version 3.1.1 has a reflected Cross-Site Scripting vulnerability in the POST parameter &quot;share_counts&quot;. Both unauthenticated and authenticated attacks are possible Edit (WPScanTeam) The original report stated the issue as being fixed in 3.2.0, however a CSRF nonce has been added inste...

Affected:
up to 3.2.0
Fixed in:
3.2.0

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 3.2.1

unknown

The version 3.2.0 attempted to fix a reflected Cross-Site Scripting issue, by adding a CSRF check, which does not fully remediate it as unauthenticated users will all have the same nonce generated (and valid for 12h to 24h, or 2 WP ticks). Only unauthenticated users can be attacked with this issue. The plugin also a...

Affected:
up to 3.2.1
Fixed in:
3.2.1

Simple Social Media Share Buttons &#8211; Social Sharing for Everyone [simple-social-buttons] < 2.0.22

unknown

The Simple Social Media Share Buttons &ndash; Social Sharing for Everyone WordPress plugin was affected by an Authenticated Option Injection security vulnerability.

Affected:
up to 2.0.22
Fixed in:
2.0.22

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database