Ed's Social Share
Ed's Social Share has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Ed's Social Share has a vendor fix available, so running the current release closes it.
All of these findings were reported by zakaria. Ed's Social Share is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-2501Ed's Social Share <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Read the full analysisVulnerability Records

Ed's Social Share
Author
waianaeboy702
The Ultimate Share Shortcode Plugin to share all of your sites on social media. Supported Platforms: Facebook, X (Twitter), Instagram, LinkedIn, Pinterest, YouTube, GitHub NEW: TikTok, Threads, WhatsApp, Reddit, Telegram, Truth Social Email, Print Features: Simple shortcode — just add [social_share] anywhere Toggle each platform on/off in settings NEW: Custom profile URLs for Instagram, GitHub, YouTube, TikTok, Threads NEW: Global Twitter/X handle setting NEW: Icon size option — small, medium, large NEW: Styles only load when shortcode is used (better performance) NEW: Built-in Open Graph meta tags — control the image, title, and description shown when your pages are shared NEW: Per-page share image override via meta box NEW: Default share image setting with media library upload Smart conflict detection — auto-disables Open Graph if Yoast, RankMath, AIOSEO, or Jetpack is active Beautiful animated hover effects with tooltips Fully responsive
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C