
WPUpper Share Buttons Security & Risk Analysis
wordpress.org/plugins/wpupper-share-buttonsFree social share buttons, share to Facebook, WhatsApp, Messenger, Twitter, Reddit and much more.
Is WPUpper Share Buttons Safe to Use in 2026?
Generally Safe
Score 90/100WPUpper Share Buttons has a strong security track record. Known vulnerabilities have been patched promptly.
The wpupper-share-buttons plugin, in version 3.52, exhibits a mixed security posture. While the static analysis shows a commendable lack of direct entry points like AJAX handlers, REST API routes, or shortcodes, and a good percentage of SQL queries using prepared statements and properly escaped output, there are underlying concerns. The presence of 3 flows with unsanitized paths, two of which are flagged as high severity taint issues, is a significant red flag. This indicates potential vulnerabilities where user-supplied data could be manipulated to execute unintended actions or reveal sensitive information. Furthermore, the plugin's history of 3 medium severity CVEs, including Cross-Site Request Forgery, Missing Authorization, and Cross-Site Scripting, points to past weaknesses that, despite being patched, suggest a pattern of insecure coding practices.
The plugin's strengths lie in its minimal direct attack surface and good utilization of prepared statements and output escaping. However, the high-severity taint flows and historical vulnerability types suggest that vulnerabilities might be introduced through less obvious means, such as through the handling of file operations or external HTTP requests, or via logic flaws that are not directly exposed as entry points. The fact that all 3 identified flows have unsanitized paths, with 2 being high severity, is the most critical finding from the static analysis and should be prioritized for remediation. The plugin has a history of medium vulnerabilities, and while there are no currently unpatched CVEs, the past types are concerning and suggest potential underlying coding issues that could resurface.
Key Concerns
- High severity taint flows
- Unsanitized paths in taint flows
- Medium severity CVEs in history
- File operations found
- External HTTP requests found
WPUpper Share Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WPUpper Share Buttons <= 3.51 - Cross-Site Request Forgery to Custom CSS Update
WPUpper Share Buttons <= 3.43 - Missing Authorization
WPUpper Share Buttons <= 3.42 - Authenticated (Admin+) Stored Cross-Site Scripting
WPUpper Share Buttons Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPUpper Share Buttons Attack Surface
WordPress Hooks 23
Maintenance & Trust
WPUpper Share Buttons Maintenance & Trust
Maintenance Signals
Community Trust
WPUpper Share Buttons Alternatives
Social Linkz – Lightweight and fast social media sharing plugin
social-linkz
Social Linkz plugin helps you easily share your content to social media.
Super Simple Social Share Icons
super-simple-social-share-icons
A lightweight and powerful solution for adding beautiful social sharing buttons to your WordPress site.
Super Easy Social Share
super-easy-social-share
The plugin adds social share links to your website. Includes content buttons and desktop and mobile floating bar.
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
WPUpper Share Buttons Developer Profile
1 plugin · 4K total installs
How We Detect WPUpper Share Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpupper-share-buttons/assets/css/admin.css/wp-content/plugins/wpupper-share-buttons/assets/css/front.css/wp-content/plugins/wpupper-share-buttons/assets/js/admin.js/wp-content/plugins/wpupper-share-buttons/assets/js/front.js/wp-content/plugins/wpupper-share-buttons/assets/js/highlight.pack.js/wp-content/plugins/wpupper-share-buttons/assets/js/highlight.pack.js/wp-content/plugins/wpupper-share-buttons/assets/js/admin.js/wp-content/plugins/wpupper-share-buttons/assets/js/front.jswpupper-share-buttons/assets/css/admin.css?ver=wpupper-share-buttons/assets/css/front.css?ver=wpupper-share-buttons/assets/js/admin.js?ver=wpupper-share-buttons/assets/js/front.js?ver=wpupper-share-buttons/assets/js/highlight.pack.js?ver=HTML / DOM Fingerprints
wpupper-share-buttonsdata-wpusb-idWPUSBVars