Frizzly – Social Share Buttons
Frizzly – Social Share Buttons has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Frizzly – Social Share Buttons has a vendor fix available, so running the current release closes it.
All of these findings were reported by 0xd4rk5id3. Frizzly – Social Share Buttons is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-30554Frizzly <= 1.1.0 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Frizzly – Social Share Buttons
Author
Abhishek Kumar
If you use many different plugins to add social media share buttons to your website, most likely each plugin has its own images and your website looks inconsistent. Frizzly is here to fix that. Frizzly allows you to share your posts on multiple social networks: Facebook, Twitter, Pinterest, Linkedin and more. You can easily choose on which pages the share buttons should show up and where they should be placed. Features: add share icons before and after the content of your posts add share icons over images (especially useful for websites that use images extensively) choose only share buttons that you need don’t show share buttons on certain pages (e.g. your home page) Third-party libraries This plugin bundles the following libraries, all under GPL-compatible licenses: Font Awesome 4.6.3 – font under SIL OFL 1.1, CSS under MIT – https://fontawesome.com AngularJS 1.5.8 and ngSanitize – MIT – https://angularjs.org angular-tooltips – MIT angular-drag-and-drop-lists – MIT jquery-modal – MIT The image attribute handling in the image module is adapted from the Photo Protect plugin, and the attachment-ID-by-URL helper is adapted from a snippet by Frankie Jarrett; both are credited in the source.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C