BNS Twitter Follow Button

BNS Twitter Follow Button has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for BNS Twitter Follow Button has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Chu The Anh. BNS Twitter Follow Button is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.5.33.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all BNS Twitter Follow Button vulnerabilities before they are exploited.

Most severe open issueCVSS 5.4CVE-2025-47578

BNS Twitter Follow Button <= 0.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv0.3.8

BNS Twitter Follow Button

Edward Caissie

Author

Edward Caissie

0.0(0)
0/100
Last Updated
2016-04-10 (11y ago)
Active Installs
10+
Downloads
4,560
Requires WP
3.6+
Requires PHP
0+
Tested up to
WP 4.5.33
Created
2011-06-02 (16y ago)

A widget to allow you to set the parameters of the Twitter Follow Button found here: https://twitter.com/about/resources/followbutton. This widget also creates a shortcode that can be used in posts and pages. Also to note, each instance of the shortcode or widget can use a different Twitter name so you can have multiple Twitter accounts listed on your website. Includes support of languages for the Follow Button using the two letter ISO-639-1 language code for English (en), French (fr), German (de), Italian (it), Spanish (es), Korean (ko) and Japanese (ja). * Copyright 2011-2015, Edward Caissie (email : edward.caissie@gmail.com) This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License version 2, as published by the Free Software Foundation. You may NOT assume that you can use any other version of the GPL. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA The license for this software can also likely be found here: http://www.gnu.org/licenses/gpl-2.0.html

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C