plugin

Social Pug Vulnerabilities

22 known security issues reported for the Social Pug WordPress plugin. Most recent disclosed Jul 22, 2026.

1 high 9 medium

Running Social Pug on your site? Check whether your installed version is affected.

Scan your site free

Hubbub Lite <= 1.36.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Hubbub Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.36.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 1.36.3
Fixed in:
1.36.3.1
Disclosed:
Jul 22, 2026

CVE-2026-27403 on NVD →

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.36.1

unknown

[en] The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dpsp_list_attention_search' parameter in all versions up to, and including, 1.36.0 due to insufficient input sanitization and output escaping. This makes it possible for unau...

Affected:
up to 1.36.1
Fixed in:
1.36.1
Disclosed:
Nov 6, 2025

CVE-2025-12471 on NVD →

Hubbub Lite <= 1.36.0 - Reflected Cross-Site Scripting

medium

The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dpsp_list_attention_search' parameter in all versions up to, and including, 1.36.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...

CVSS:
6.1
Affected:
up to 1.36.0
Fixed in:
1.36.1
Disclosed:
Nov 5, 2025

CVE-2025-12471 on NVD →

Hubbub Lite <= 1.35.1 - Authenticated (Subscriber+) Sensitive Information Exposure

medium

The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 1.35.1
Fixed in:
1.36.0
Disclosed:
Sep 22, 2025

CVE-2025-58007 on NVD →

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.34.4

unknown

[en] The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 1.34.4
Fixed in:
1.34.4
Disclosed:
May 15, 2025

CVE-2024-10145 on NVD →

Hubbub Lite <= 1.34.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev...

CVSS:
4.4
Affected:
up to 1.34.3
Fixed in:
1.34.4
Disclosed:
Mar 2, 2025

CVE-2024-10145 on NVD →

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.30.1

unknown

[en] Missing Authorization vulnerability in NerdPress Social Pug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Pug: from n/a through 1.30.0.

Affected:
up to 1.30.1
Fixed in:
1.30.1
Disclosed:
Dec 9, 2024

CVE-2023-49193 on NVD →

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.33.2

unknown

[en] The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for authenticated attackers, with contributor acce...

Affected:
up to 1.33.2
Fixed in:
1.33.2
Disclosed:
Apr 9, 2024

CVE-2024-2501 on NVD →

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.33.1

unknown

[en] The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.

Affected:
up to 1.33.1
Fixed in:
1.33.1
Disclosed:
Apr 1, 2024

CVE-2024-1526 on NVD →

Hubbub Lite – Fast, Reliable Social Network Sharing Buttons <= 1.33.1 - PHP Object Injection

high

The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.33.1 via deserialization of untrusted input via the 'dpsp_maybe_unserialize' function. This makes it possible for authenticated attackers, with contributor access an...

CVSS:
7.5
Affected:
up to 1.33.1
Fixed in:
1.33.2
Disclosed:
Mar 27, 2024

CVE-2024-2501 on NVD →

Hubbub Lite <= 1.31.0 - Unauthenticated Information Exposure

medium

The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.33.0 via opengraph tags. This makes it possible for unauthenticated attackers to view short excerpts of password protected posts.

CVSS:
5.3
Affected:
up to 1.33.0
Fixed in:
1.33.1
Disclosed:
Mar 11, 2024

CVE-2024-1526 on NVD →

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.32.0

unknown

[en] The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.32.0
Fixed in:
1.32.0
Disclosed:
Jan 16, 2024

CVE-2023-7154 on NVD →

Hubbub Lite <= 1.31.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Hubbub Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.31.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbi...

CVSS:
4.4
Affected:
up to 1.31.1
Fixed in:
1.32.0
Disclosed:
Jan 11, 2024

CVE-2023-7154 on NVD →

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.2.6

unknown

Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Social Pug Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit...

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Dec 9, 2023

Social Pug <= 1.30.0 - Missing Authorization via multiple admin_init actions

medium

The Social Pug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple functions that run on admin_init in versions up to, and including, 1.20.3. This makes it possible for unauthenticated attackers to dismiss admin notifications and update the database.

CVSS:
5.3
Affected:
up to 1.30.0
Fixed in:
1.30.1
Disclosed:
Dec 1, 2023

CVE-2023-49193 on NVD →

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.19.0

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Grow Social plugin (versions <= 1.18.2). Update the WordPress Grow Social plugin to the latest available version (at least 1.19.0).

Affected:
up to 1.19.0
Fixed in:
1.19.0
Disclosed:
Jun 13, 2022

Grow Social <= 1.18.2 - Reflected Cross-Site Scripting

medium

The Grow Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.18.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

CVSS:
6.1
Affected:
up to 1.18.2
Fixed in:
1.19.0
Disclosed:
Jul 8, 2021

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.19.0

unknown

The Grow Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.18.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

Affected:
up to 1.19.0
Fixed in:
1.19.0
Disclosed:
Jul 8, 2021

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.2.6

unknown

[en] The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jan 9, 2019

CVE-2016-10736 on NVD →

Grow Social <= 1.2.5 - Reflected Cross-Site Scripting

medium

The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.

CVSS:
6.1
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Dec 9, 2016

CVE-2016-10736 on NVD →

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.2.6

unknown

This plugin is prone to a cross site scripting vulnerability. It allows attackers to inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Dec 9, 2016

Hubbub Lite &#8211; Fast, free social sharing and follow buttons [social-pug] < 1.19.0

unknown

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 1.19.0
Fixed in:
1.19.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database