WordPress security by component
Share This Image
Plugin description
Share This Image is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Apr 29, 2026; the highest CVE/CNA score is 7.2.
Plugin slug:
share-this-imageLatest vulnerability
CVE-2026-42641: Share This Image: Server-side request forgery
Share This Image is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 2.14.
| Safe version |
|
||
|---|---|---|---|
| Apr 29, 2026 |
CVE-2026-42641
Share This Image: Server-side request forgery
Share This Image is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 2.14.
|
2.15 |
CVE5.4
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39563
Share This Image: A security weakness
Share This Image is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.12.
|
2.13 |
CVE5.3
NVDPending
|
| Feb 03, 2026 |
CVE-2026-25010
Share This Image: A security weakness
Share This Image is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Oct 06, 2024 |
CVE-2024-47326
Share This Image: Cross-site scripting
Share This Image is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Sep 17, 2024 |
CVE-2024-8761
Share This Image: An open redirect
Share This Image is affected by an open redirect. The vulnerable path is reachable without authentication. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Sep 05, 2024 |
CVE-2024-8363
Share This Image: Cross-site scripting
Share This Image is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Aug 31, 2024 |
CVE-2024-8108
Share This Image: Cross-site scripting
Share This Image is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-33930
Share This Image: An open redirect
Share This Image is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE4.7
NVDPending
|
| Jan 02, 2018 |
CVE-2017-18015
Share This Image: Cross-site scripting
Share This Image is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|