Social Hashtags
Social Hashtags has one disclosed vulnerability in the WordSec catalog, all reported in 2012; it remains unpatched as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 4.8 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Social Hashtags has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2012.
All of these findings were reported by Arsan. Social Hashtags is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.1.42.
Social Hashtags <= 3.0.0 - Cross-Site Scripting
Read the full analysisVulnerability Records

Social Hashtags
Author
shanaver
Grabs images & videos matching any hashtag from social APIs like instagram & youtube. Stores thumbnails & details locally for each one in a custom post type so you have full control over the content on your site. This allows you to categorize, make private/public, etc and include them any wayt hat you like on your pages. Extendable to include twitter, telportd and others as well. We first developed this for the original Kony2012 site, it was a huge hit. Sorry that it took so long to get it into the WordPress plugins. Update Plans We are going to upgrade twitter to oAuth, and clean up the layout.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C