ShareThis Share Buttons Security & Risk Analysis

wordpress.org/plugins/sharethis-share-buttons

Grow your website traffic and engagement by enabling one-click sharing with the free ShareThis Share Buttons plugin. The plugin is free (no upgrades a …

20K active installs v2.3.7 PHP + WP 5.5+ Updated Aug 8, 2025
share-buttonsshare-thissharethissocial-buttonssocial-sharing
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 22, 2024
Safety Verdict

Is ShareThis Share Buttons Safe to Use in 2026?

Generally Safe

Score 99/100

ShareThis Share Buttons has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 22, 2024Updated 7mo ago
Risk Assessment

The "sharethis-share-buttons" plugin, version 2.3.7, exhibits a generally good security posture with strong adherence to secure coding practices. The static analysis reveals a commendable absence of directly exploitable entry points like AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. Furthermore, all identified SQL queries are properly prepared, and there are no direct file operations, significantly reducing the risk of SQL injection or file manipulation vulnerabilities.

However, there are areas for improvement. The taint analysis identified two flows with unsanitized paths, which, while not flagged as critical or high severity in this analysis, represent potential avenues for vulnerabilities if exploited. The output escaping, while generally good at 74%, means that a significant portion of output (26%) is not properly escaped, creating a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved.

The plugin's vulnerability history includes one medium severity CVE related to XSS, last patched on May 22, 2024. While this vulnerability is no longer unpatched, it highlights a historical susceptibility to XSS. The presence of only one medium severity CVE in the past, coupled with the current good practices in the code, suggests that the developers are responsive to security issues. Overall, the plugin is reasonably secure, but the remaining unsanitized paths and a notable percentage of unescaped output warrant attention for future development.

Key Concerns

  • Unsanitized paths in taint flows
  • Significant portion of output not escaped
  • Past medium severity XSS vulnerability
Vulnerabilities
1

ShareThis Share Buttons Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-3648medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ShareThis Share Buttons <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via sharethis-inline-buttons Shortcode

May 22, 2024 Patched in 2.3.1 (10d)
Code Analysis
Analyzed Mar 16, 2026

ShareThis Share Buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
75
211 escaped
Nonce Checks
8
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

74% escaped286 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
update_list (php\class-minute-control.php:107)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ShareThis Share Buttons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_noticessharethis-share-buttons.php:39
Maintenance & Trust

ShareThis Share Buttons Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 8, 2025
PHP min version
Downloads613K

Community Trust

Rating70/100
Number of ratings26
Active installs20K
Developer Profile

ShareThis Share Buttons Developer Profile

ShareThis

5 plugins · 21K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect ShareThis Share Buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sharethis-share-buttons/assets/css/admin.css/wp-content/plugins/sharethis-share-buttons/assets/js/admin.js/wp-content/plugins/sharethis-share-buttons/assets/js/frontend.js/wp-content/plugins/sharethis-share-buttons/assets/js/sharethis.js
Script Paths
/wp-content/plugins/sharethis-share-buttons/assets/js/admin.js/wp-content/plugins/sharethis-share-buttons/assets/js/frontend.js/wp-content/plugins/sharethis-share-buttons/assets/js/sharethis.js
Version Parameters
sharethis-share-buttons/assets/css/admin.css?ver=sharethis-share-buttons/assets/js/admin.js?ver=sharethis-share-buttons/assets/js/frontend.js?ver=sharethis-share-buttons/assets/js/sharethis.js?ver=

HTML / DOM Fingerprints

CSS Classes
sharethis-inline-share-buttonsst_share_twitterst_share_whatsappst_share_facebookst_share_linkedinst_share_emailst_share_redditst_share_pinterest+41 more
Data Attributes
data-sharethis-widgetdata-categorydata-networkdata-textdata-urldata-shortener+54 more
JS Globals
ShareThisMinuteControl
Shortcode Output
[sharethis]
FAQ

Frequently Asked Questions about ShareThis Share Buttons