WP Socializer – Simple & Easy Social Media Share Icons Security & Risk Analysis

wordpress.org/plugins/wp-socializer

Simple & easy plugin to add social media sharing icons, buttons like Facebook, Twitter, WhatsApp, Instagram & more

10K active installs v7.9 PHP 5.3+ WP 5.0+ Updated Jan 11, 2025
shareshare-buttonssocial-mediasocial-sharesocial-sharing
92
A · Safe
CVEs total1
Unpatched0
Last CVEAug 23, 2022
Safety Verdict

Is WP Socializer – Simple & Easy Social Media Share Icons Safe to Use in 2026?

Generally Safe

Score 92/100

WP Socializer – Simple & Easy Social Media Share Icons has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 23, 2022Updated 1yr ago
Risk Assessment

The "wp-socializer" v7.9 plugin exhibits a mixed security posture. While it demonstrates good practices in several areas, such as using prepared statements for all SQL queries and performing a reasonable number of capability checks, significant concerns exist regarding its attack surface. The presence of two AJAX handlers without authentication checks presents a direct and exploitable pathway for unauthenticated users to potentially interact with sensitive plugin functionalities. This, combined with a generally high number of total entry points, suggests a need for stricter access control across the board.

The vulnerability history, though currently showing no unpatched issues, reveals a past medium-severity vulnerability related to Cross-Site Scripting (XSS). This pattern, coupled with a less than ideal output escaping rate (70%), indicates a potential for similar vulnerabilities to re-emerge if input sanitization and output encoding are not consistently and robustly implemented throughout the codebase. The taint analysis, while showing no critical or high severity flows, is limited in scope with only two flows analyzed, making it difficult to ascertain the complete security of data handling within the plugin.

In conclusion, "wp-socializer" v7.9 has some strong security foundations, particularly in database interaction. However, the unprotected AJAX endpoints are a critical weakness that requires immediate attention. The historical XSS vulnerability and the imperfect output escaping suggest that developers should prioritize a comprehensive review of input validation and output encoding to prevent future attacks. The plugin's overall security could be significantly improved by securing all entry points and ensuring rigorous sanitization and escaping for all user-supplied data.

Key Concerns

  • Unprotected AJAX handlers
  • Output escaping (70% proper)
  • Bundled outdated library (TinyMCE v1.3)
  • Past medium severity XSS vulnerability
Vulnerabilities
1

WP Socializer – Simple & Easy Social Media Share Icons Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-2763medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Socializer – Simple & Easy Social Media Share Icons <= 7.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Aug 23, 2022 Patched in 7.3 (518d)
Code Analysis
Analyzed Mar 16, 2026

WP Socializer – Simple & Easy Social Media Share Icons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
92
212 escaped
Nonce Checks
5
Capability Checks
12
File Operations
0
External Requests
3
Bundled Libraries
1

Bundled Libraries

TinyMCE1.3

Output Escaping

70% escaped304 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
popup_editor (admin\pages\follow-icons.php:263)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

WP Socializer – Simple & Easy Social Media Share Icons Attack Surface

Entry Points9
Unprotected2

AJAX Handlers 6

authwp_ajax_wpsr_admin_ajaxadmin\admin.php:30
authwp_ajax_wpsr_follow_icons_editoradmin\pages\follow-icons.php:15
authwp_ajax_wpsr_import_ajaxcore\import-export.php:13
authwp_ajax_wpsr_location_rulescore\location-rules.php:14
authwp_ajax_wpsr_share_countcore\share-counter.php:13
noprivwp_ajax_wpsr_share_countcore\share-counter.php:14

Shortcodes 3

[wpsr_share_icons] core\shortcodes.php:11
[wpsr_follow_icons] core\shortcodes.php:13
[wpsr_share_link] core\shortcodes.php:15
WordPress Hooks 40
actioninitadmin\admin.php:18
actionadmin_menuadmin\admin.php:21
actionadmin_enqueue_scriptsadmin\admin.php:24
actionadmin_print_scriptsadmin\admin.php:27
actionplugins_loadedadmin\admin.php:35
filteradmin_footer_textadmin\admin.php:37
filterwpsr_register_admin_pageadmin\pages\floating-sharebar.php:13
filterwpsr_register_admin_pageadmin\pages\follow-icons.php:13
filterwpsr_register_admin_pageadmin\pages\general-settings.php:13
actionwpsr_form_general_settingsadmin\pages\general-settings.php:15
filterwpsr_register_admin_pageadmin\pages\import-export.php:13
filterwpsr_register_admin_pageadmin\pages\share-icons.php:13
filterwpsr_register_admin_pageadmin\pages\shortcodes.php:13
filterwpsr_register_admin_pageadmin\pages\text-sharebar.php:13
actionadmin_enqueue_scriptsadmin\post-settings.php:9
actionadd_meta_boxesadmin\post-settings.php:11
actionsave_postadmin\post-settings.php:13
actionadmin_initadmin\tools.php:10
filtermce_buttonsadmin\tools.php:16
filtermce_external_pluginsadmin\tools.php:18
actioninitcore\includes.php:16
actionwp_enqueue_scriptscore\includes.php:19
actionwp_footercore\includes.php:22
actionwp_footercore\templates\floating-sharebar.php:13
actionwp_footercore\templates\follow-icons.php:13
actionwp_footercore\templates\popups.php:17
actioninitcore\templates\share-icons.php:13
filterthe_contentcore\templates\share-icons.php:40
filterthe_excerptcore\templates\share-icons.php:41
actionwp_footercore\templates\text-sharebar.php:13
filterwpsr_register_widgetcore\widgets\facebook.php:20
filterwpsr_register_admin_pagecore\widgets\facebook.php:21
filterwpsr_register_widgetcore\widgets\follow-icons.php:20
filterwpsr_register_admin_pagecore\widgets\follow-icons.php:21
filterwpsr_register_widgetcore\widgets\pinterest.php:20
filterwpsr_register_admin_pagecore\widgets\pinterest.php:21
filterwpsr_register_widgetcore\widgets\twitter.php:20
filterwpsr_register_admin_pagecore\widgets\twitter.php:21
actionwidgets_initcore\widgets.php:15
actionadmin_enqueue_scriptscore\widgets.php:17
Maintenance & Trust

WP Socializer – Simple & Easy Social Media Share Icons Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 11, 2025
PHP min version5.3
Downloads998K

Community Trust

Rating90/100
Number of ratings128
Active installs10K
Developer Profile

WP Socializer – Simple & Easy Social Media Share Icons Developer Profile

vaakash

6 plugins · 133K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
157 days
View full developer profile
Detection Fingerprints

How We Detect WP Socializer – Simple & Easy Social Media Share Icons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-socializer/admin/css/admin.css/wp-content/plugins/wp-socializer/admin/js/admin.js/wp-content/plugins/wp-socializer/core/css/style.css/wp-content/plugins/wp-socializer/core/css/share-icons.css/wp-content/plugins/wp-socializer/core/css/floating-sharebar.css/wp-content/plugins/wp-socializer/core/css/follow-icons.css/wp-content/plugins/wp-socializer/core/css/text-sharebar.css/wp-content/plugins/wp-socializer/core/css/popups.css+6 more
Generator Patterns
WP Socializer v7.9
Script Paths
/wp-content/plugins/wp-socializer/admin/js/admin.js
Version Parameters
wp-socializer/style.css?ver=wp-socializer/share-icons.css?ver=wp-socializer/floating-sharebar.css?ver=wp-socializer/follow-icons.css?ver=wp-socializer/text-sharebar.css?ver=wp-socializer/popups.css?ver=wp-socializer/share-icons.js?ver=wp-socializer/floating-sharebar.js?ver=wp-socializer/follow-icons.js?ver=wp-socializer/text-sharebar.js?ver=wp-socializer/popups.js?ver=wp-socializer/share-counter.js?ver=wp-socializer/admin.css?ver=wp-socializer/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpsr_titletitle-countback_btnwpsr_headerwpsr_formwpsr_optionswpsr_sidebarwpsr_content+3 more
HTML Comments
<!-- MAIN CONTENT --><!-- SOCIALIZER CORE --><!-- ADMIN CORE -->
Data Attributes
data-wpsr-iddata-wpsr-type
JS Globals
WPSR_DATAwpsr_ajax_urlwpsr_admin_varswpsr_data
Shortcode Output
[wp_socializer_share_icons][wp_socializer_floating_sharebar][wp_socializer_follow_icons][wp_socializer_text_sharebar]
FAQ

Frequently Asked Questions about WP Socializer – Simple & Easy Social Media Share Icons