Shareaholic operates a content-sharing and social-media optimization platform deployed across WordPress and similar publishing environments, where its vulnerability profile concentrates in web-application input handling and authorization boundaries. The durable signal centers on cross-site scripting, cross-site request forgery, code injection, and access-control weaknesses that recur across its core plugins and services—a pattern characteristic of web-facing extensions with broad integration into third-party content pipelines. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shareaholic over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0594MEDIUM The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauth | Jul 25, 2022 | 5.3 | 31 | NO | YES |
CVE-2021-24537HIGH The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened environment (ie with DISALLOW_FILE_EDIT, DISALLOW_FILE_MODS | Nov 8, 2021 | 7.2 | 24 | NO | NO |
Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTM | Apr 14, 2015 | 3.5 | 20 | NO | YES |
CVE-2024-24709MEDIUM Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Shareaholic: from n/a through 9.7.11 | Jun 17, 2026 | 4.3 | 19 | NO | NO |
CVE-2023-4889MEDIUM The Shareaholic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shareaholic' shortcode in versions up to, and including, 9.7.8 due to insufficient input sani | Nov 15, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-41612MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shareaholic Similar Posts plugin <= 3.1.6 versions. | Apr 24, 2023 | 4.8 | 19 | NO | NO |
CVE-2013-3256MEDIUM Cross-site request forgery (CSRF) vulnerability in the Shareaholic SexyBookmarks plugin 6.1.4.0 for WordPress allows remote attackers to hijack the authentication of users for requ | Aug 8, 2013 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shareaholic.
Media articles that mention a CVE ID that affects a product developed by Shareaholic — matched by CVE ID, not by vendor name.