Korea SNS Security & Risk Analysis

wordpress.org/plugins/korea-sns

Puts Korea social share buttons in post and page. support kakaotalk, naver (line, band, cafe), facebook, twitter, telegram

4K active installs v1.7.0 PHP + WP 5.0+ Updated May 15, 2024
kakaokakao-talkkakaostorypostshare
61
C · Use Caution
CVEs total2
Unpatched1
Last CVEFeb 18, 2026
Safety Verdict

Is Korea SNS Safe to Use in 2026?

Use With Caution

Score 61/100

Korea SNS has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

2 known CVEs 1 unpatched Last CVE: Feb 18, 2026Updated 2yr ago
Risk Assessment

The korea-sns plugin v1.7.0 exhibits a generally good security posture, with a low attack surface and a strong adherence to best practices regarding SQL queries and nonce checks. The static analysis shows no critical or high-severity taint flows and a robust use of prepared statements for SQL. However, a significant concern lies in the output escaping, where a large majority of outputs are not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the plugin has a history of known vulnerabilities, specifically a medium-severity Cross-Site Request Forgery (CSRF) in its past. While currently unpatched vulnerabilities are zero, this history suggests a pattern that, when combined with the output escaping issues, warrants careful consideration.

In conclusion, while the plugin demonstrates strengths in areas like SQL security and input validation (via nonces and capabilities), the prevalent lack of proper output escaping presents a clear and present danger for XSS attacks. The past CSRF vulnerability, though resolved, also highlights the need for vigilance. Users should be aware that despite the current lack of critical issues in static analysis, the unescaped output is a significant weakness that could be exploited. The plugin's overall security is thus weakened by this oversight, despite otherwise positive indicators.

Key Concerns

  • Poor output escaping
  • Past medium severity CVEs
Vulnerabilities
2 published

Korea SNS Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-39667medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Korea SNS <= 1.7.0 - Authenticated (Author+) Stored Cross-Site Scripting

Feb 18, 2026Unpatched
CVE-2023-47670medium · 4.3Cross-Site Request Forgery (CSRF)

Korea SNS <= 1.6.4 - Cross-Site Request Forgery via kon_tergos_options

Nov 8, 2023 Patched in 1.6.5 (139d)
Version History

Korea SNS Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Korea SNS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

26% escaped27 total outputs
Attack Surface

Korea SNS Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[korea_sns_button] korea_sns.php:30
WordPress Hooks 6
actioninitkorea_sns.php:25
filterthe_contentkorea_sns.php:26
filterthe_excerptkorea_sns.php:27
filterplugin_action_linkskorea_sns.php:28
actionadmin_menukorea_sns.php:29
filterthe_contentkorea_sns.php:77
Maintenance & Trust

Korea SNS Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 15, 2024
PHP min version
Downloads73K

Community Trust

Rating100/100
Number of ratings5
Active installs4K
Developer Profile

Korea SNS Developer Profile

Jongmyoung Kim

3 plugins · 4K total installs

63
trust score
Avg Security Score
77/100
Avg Patch Time
139 days
View full developer profile
Detection Fingerprints

How We Detect Korea SNS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/korea-sns/korea_sns.css/wp-content/plugins/korea-sns/korea_sns.js
Script Paths
https://developers.kakao.com/sdk/js/kakao.min.js/wp-content/plugins/korea-sns/korea_sns.js
Version Parameters
korea_sns.css?ver=korea_sns.js?ver=

HTML / DOM Fingerprints

CSS Classes
korea-snskorea-sns-buttonkorea-sns-facebookkorea-sns-twitterkorea-sns-telegramkorea-sns-naverlinekorea-sns-naverbandkorea-sns-naverblog+8 more
Data Attributes
OnClick
JS Globals
SendSNS
Shortcode Output
<div class="korea-sns-shortcode">
FAQ

Frequently Asked Questions about Korea SNS