HTML Social Share Buttons
HTML Social Share Buttons has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for HTML Social Share Buttons has a vendor fix available, so running the current release closes it.
All of these findings were reported by Peter Thaleikis. HTML Social Share Buttons is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-9849Html Social share buttons <= 2.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

HTML Social Share Buttons
Author
Alimuzzaman Alim
HTML Social Share Buttons adds server-rendered HTML and CSS share buttons and profile links to posts, pages, sidebars, and builder layouts. By default, the plugin adds no frontend JavaScript. Bundled icons load from your own site, and optional Google Social Analytics stays off unless you enable it. Use the Social Share or Social Links block, automatic placement, the classic widget, Elementor, WPBakery, a shortcode, or PHP. Choose from six bundled icon sets and square or circle buttons. Why this plugin: HTML + CSS by default: Server-rendered share and profile links with no frontend plugin JavaScript unless optional analytics is enabled. Private by default: Bundled icons load from your site; optional analytics stays disabled until you enable it. Place anywhere: Automatic before/after and floating placement, two blocks, a widget, Elementor, WPBakery, shortcodes, and PHP. Share and follow separately: Share actions open a composer for the current page; profile links open the configured profile or email destination. Current destinations: Facebook, X, LinkedIn, Pinterest, Telegram, Bluesky, and email. Choose the presentation: Legacy preserves the existing pack behavior; Minimal, Framed, and Soft shadow add modern frontend styles. Other features: Optional global profile/contact links with per-placement inherit or suppress controls. Audience controls for the content author, other logged-in users, and logged-out visitors. Bootstrap Solid as the default for new installations, plus Flat, Long Shadow, Prajin, and Tabler Outline. Existing content configured with the historical Default pack keeps rendering it without migration. Square buttons in every set; circle buttons in Flat, Long Shadow, Prajin, Bootstrap Solid, and Tabler Outline. Responsive floating rails that become centered, wrapping rows at 600px and below. Per-network URL templates and exclusions by post/page ID, slug, or searchable content. Translation-ready admin and editor strings. Shortcode examples: [zm_sh_btn iconset="long-shadows" iconset_type="square" icons="facebook,x,linkedin,pinterest,mail" class="in_widget"] [html-social-share-buttons iconset="tabler-outline" iconset_type="circle" profile_links_mode="inherit"] The historical [zm_sh_btn] tag remains supported. Use class="in_widget" for a horizontal row. Credits Original historical-design credit: Hakan Ertan, tonicons.com. Prajin remains credited for the historical Prajin pack. Maintainer attestation (2026-08-12): the Flat, Long Shadow, and Prajin PNG packs are used with authorization from their respective rights holders. The repository does not archive the written authorizations or license instruments, so this is a maintainer statement, not independent legal verification. The Default PNG pack is retained under the release owner’s accepted compatibility exception. That decision is not an independent source, license, redistribution, or clearance claim. Generated Bootstrap Icons and Tabler Icons sources and their license notices are included with the plugin. See resources/iconsets/ASSET-SOURCES.md in the source repository for the current provenance record.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C