Addtoany produces a widely embedded social-sharing widget that extends across numerous websites and publishing platforms, creating a distributed attack surface despite the vendor's narrow product scope. The observed vulnerability pattern centers on cross-site scripting weaknesses in the share-button component, reflecting the challenges of secure content injection in a widget deployed across diverse host contexts. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Addtoany over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24568MEDIUM The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as a | Sep 6, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-24616MEDIUM The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting | Nov 8, 2021 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Addtoany.
Media articles that mention a CVE ID that affects a product developed by Addtoany — matched by CVE ID, not by vendor name.