Simple Share Follow Button
Simple Share Follow Button has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Simple Share Follow Button has a vendor fix available, so running the current release closes it.
Simple Share Follow Button is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
Simple Share Follow Button <= 1.03 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records
Simple Share Follow Button
Author
Katsushi Kawamori
Displays the Share button and Follow button. Button X(Twitter) Facebook Instagram Youtube WordPress Github Line Pocket Hatena Rss Feedly View The share button is displayed immediately after the content. The follow button is displayed on the top right by default. It can be changed in the settings page. The follow button can also be displayed with a shortcode. Filter for share button Each initial value indicates the position from the left side. If the value is null, it will be hidden. ssfb_share_twitter : initial value 1 ssfb_share_facebook : initial value 2 ssfb_share_pocket : initial value 3 ssfb_share_hatena : initial value 4 ssfb_share_line : initial value 5 /** ================================================== * Filter for hide X(twitter). * */ add_filter( 'ssfb_share_twitter', function(){ return null; }, 10, 1 ); /** ================================================== * Filter for position X(twitter) and facebook. * */ add_filter( 'ssfb_share_twitter', function(){ return 2; }, 10, 1 ); add_filter( 'ssfb_share_facebook', function(){ return 1; }, 10, 1 ); If you want to hide it, set it to false. ssfb_share : initial value true /** ================================================== * Filter for hide all. * */ add_filter( 'ssfb_share', function(){ return false; }, 10, 1 ); If you want to hide it by post ID, set it to false. ssfb_share_id : initial value true /** ================================================== * Display by post ID or not for Simple Share Follow Button * * @param bool $flag view. * @param int $pid post ID. * @since 1.00 */ function ssfb_share_post_id( $flag, $pid ) { if ( 1567 === $pid ) { $flag = false; } return $flag; } add_filter( 'ssfb_share_id', 'ssfb_share_post_id', 10, 2 ); If you want to hide it by post type, set it to false. ssfb_share_type : initial value true /** ================================================== * Display by post type or not for Simple Share Follow Button * * @param bool $flag view. * @param string $type post type. * @since 1.00 */ function ssfb_share_post_type( $flag, $type ) { if ( 'page' === $type || 'attachment' === $type ) { $flag = false; } return $flag; } add_filter( 'ssfb_share_type', 'ssfb_share_post_type', 10, 2 ); icon [IcoMoon – Free https://icomoon.io/] License GPL / CC BY 4.0
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C