Sharethis develops social-sharing and analytics plugins and embeddable widgets for web publishers, a portfolio that sits across many third-party websites and relies heavily on JavaScript injection and user-authentication flows. Its vulnerability profile concentrates on web-layer weakness classes including cross-site scripting, cross-site request forgery, and missing authorization checks, patterns endemic to client-side sharing and tracking code embedded in untrusted third-party contexts. The vendor's disclosures have a tendency toward public exploit availability, and live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sharethis over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4717MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of | Jul 3, 2014 | 6.8 | 33 | NO | YES |
CVE-2021-24438MEDIUM The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an a | Aug 30, 2021 | 6.1 | 21 | NO | NO |
CVE-2024-3648MEDIUM The ShareThis Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sharethis-inline-button' shortcode in all versions up to, and includ | May 23, 2024 | 5.4 | 19 | NO | NO |
CVE-2021-36848MEDIUM Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versions <= 2.0.4 | Apr 11, 2022 | 4.8 | 19 | NO | NO |
CVE-2013-3479MEDIUM Cross-site request forgery (CSRF) vulnerability in the ShareThis plugin before 7.0.6 for WordPress allows remote attackers to hijack the authentication of administrators for reques | Sep 5, 2013 | 6.8 | 18 | NO | NO |
CVE-2025-1507MEDIUM The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_actions() funct | Mar 14, 2025 | 5.3 | 17 | NO | NO |
CVE-2024-4094MEDIUM The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cr | Jun 18, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sharethis.
Media articles that mention a CVE ID that affects a product developed by Sharethis — matched by CVE ID, not by vendor name.