Ultimatelysocial operates a focused portfolio of WordPress plugins centered on social-media sharing and marketing functionality, a niche but widely embedded class of web-based tools. Its vulnerability profile concentrates on web-application input and authorization weaknesses—cross-site request forgery, cross-site scripting, improper access control, and sensitive-information exposure—which reflect the plugins' role in handling user data and social-platform integration. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ultimatelysocial over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5602HIGH The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to m | Oct 20, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-5070MEDIUM The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save | Oct 20, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-41238MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UltimatelySocial Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.3 versions. | Sep 27, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-3977MEDIUM Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation | Jul 28, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-0958MEDIUM Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called | Jul 28, 2023 | 6.5 | 17 | NO | NO |
CVE-2023-1166MEDIUM The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Sc | Jun 27, 2023 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ultimatelysocial.
Media articles that mention a CVE ID that affects a product developed by Ultimatelysocial — matched by CVE ID, not by vendor name.