HTML Social Share Buttons

HTML Social Share Buttons has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for HTML Social Share Buttons has a vendor fix available, so running the current release closes it.

All of these findings were reported by Peter Thaleikis. HTML Social Share Buttons is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all HTML Social Share Buttons vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-9849

Html Social share buttons <= 2.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
HTML Social Share Buttons banner
Latestv3.1.0

HTML Social Share Buttons

Alimuzzaman Alim

Author

Alimuzzaman Alim

4.7(15)
94/100
Last Updated
2026-08-27 (17d ago)
Active Installs
50+
Downloads
29,449
Requires WP
5.3+
Requires PHP
7.0+
Tested up to
WP 7.1
Created
2013-11-10 (13y ago)

HTML Social Share Buttons adds server-rendered HTML and CSS share buttons and profile links to posts, pages, sidebars, and builder layouts. By default, the plugin adds no frontend JavaScript. Bundled icons load from your own site, and optional Google Social Analytics stays off unless you enable it. Use the Social Share or Social Links block, automatic placement, the classic widget, Elementor, WPBakery, a shortcode, or PHP. Choose from six bundled icon sets and square or circle buttons. Why this plugin: HTML + CSS by default: Server-rendered share and profile links with no frontend plugin JavaScript unless optional analytics is enabled. Private by default: Bundled icons load from your site; optional analytics stays disabled until you enable it. Place anywhere: Automatic before/after and floating placement, two blocks, a widget, Elementor, WPBakery, shortcodes, and PHP. Share and follow separately: Share actions open a composer for the current page; profile links open the configured profile or email destination. Current destinations: Facebook, X, LinkedIn, Pinterest, Telegram, Bluesky, and email. Choose the presentation: Legacy preserves the existing pack behavior; Minimal, Framed, and Soft shadow add modern frontend styles. Other features: Optional global profile/contact links with per-placement inherit or suppress controls. Audience controls for the content author, other logged-in users, and logged-out visitors. Bootstrap Solid as the default for new installations, plus Flat, Long Shadow, Prajin, and Tabler Outline. Existing content configured with the historical Default pack keeps rendering it without migration. Square buttons in every set; circle buttons in Flat, Long Shadow, Prajin, Bootstrap Solid, and Tabler Outline. Responsive floating rails that become centered, wrapping rows at 600px and below. Per-network URL templates and exclusions by post/page ID, slug, or searchable content. Translation-ready admin and editor strings. Shortcode examples: [zm_sh_btn iconset="long-shadows" iconset_type="square" icons="facebook,x,linkedin,pinterest,mail" class="in_widget"] [html-social-share-buttons iconset="tabler-outline" iconset_type="circle" profile_links_mode="inherit"] The historical [zm_sh_btn] tag remains supported. Use class="in_widget" for a horizontal row. Credits Original historical-design credit: Hakan Ertan, tonicons.com. Prajin remains credited for the historical Prajin pack. Maintainer attestation (2026-08-12): the Flat, Long Shadow, and Prajin PNG packs are used with authorization from their respective rights holders. The repository does not archive the written authorizations or license instruments, so this is a maintainer statement, not independent legal verification. The Default PNG pack is retained under the release owner’s accepted compatibility exception. That decision is not an independent source, license, redistribution, or clearance claim. Generated Bootstrap Icons and Tabler Icons sources and their license notices are included with the plugin. See resources/iconsets/ASSET-SOURCES.md in the source repository for the current provenance record.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C