FireCask Like & Share Button
FireCask Like & Share Button has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for FireCask Like & Share Button has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. FireCask Like & Share Button is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-11226FireCask Like & Share Button <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter
Read the full analysisVulnerability Records

FireCask Like & Share Button
Author
Alex Moss
Insert the Facebook Like and/or Send button to any post, page or template with this simple plugin. Also lets you add them via shortcode anywhere in your site! Simply install the plugin and follow the instructions on the Settings page. WordPress Development by FireCask. You can also insert the comment box as a shortcode into any post, page or template and use your own settings for each time you do it! Simply use the shortcode [fbcomments]
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C