Description
Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media Share Buttons | MashShare: from n/a through 4.0.47.
Published: 2025-01-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MashShare plugin, used within WordPress from earlier versions through 4.0.47, contains a missing authorization flaw that permits any visitor to reach administrative configuration pages without authentication. This breach results in the ability to modify the plugin’s settings, alter social sharing behavior, or disable the plugin entirely. The underlying weakness is documented as CWE‑862 and constitutes an access control failure rather than a data breach or code execution vulnerability.

Affected Systems

WordPress sites that have installed the DearHive Social Media Share Buttons plugin, commonly referred to as MashShare, are at risk if the installed version is 4.0.47 or older. No specific server software or operating system is referenced, so the vulnerability applies broadly across any environment running WordPress where the affected plugin is active.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1 % suggests low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the flaw allows unauthenticated manipulation of administrative URLs, the most likely attack vector is over standard HTTP requests to the plugin’s administrative endpoints, meaning remote attackers can trigger it by sending crafted requests from any network that can reach the site.

Generated by OpenCVE AI on May 1, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MashShare to a version newer than 4.0.47 to eliminate the missing authorization flaw.
  • If an upgrade is not immediately possible, deactivate or uninstall the MashShare plugin to prevent exposed administrative interfaces.
  • Review and harden user roles and capabilities on the WordPress site to ensure that only trusted administrators have access to plugin configuration settings, reducing the risk of accidental exposure.

Generated by OpenCVE AI on May 1, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2719 Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media Share Buttons | MashShare: from n/a through 4.0.47.
History

Tue, 28 Apr 2026 19:30:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare mashsharer.This issue affects Social Media Share Buttons | MashShare: from n/a through <= 4.0.47. Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media Share Buttons | MashShare: from n/a through 4.0.47.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media Share Buttons | MashShare: from n/a through 4.0.47. Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare mashsharer.This issue affects Social Media Share Buttons | MashShare: from n/a through <= 4.0.47.
References

Tue, 07 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media Share Buttons | MashShare: from n/a through 4.0.47.
Title WordPress MashShare plugin <= 4.0.47 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:10:59.558Z

Reserved: 2025-01-03T13:16:25.401Z

Link: CVE-2025-22319

cve-icon Vulnrichment

Updated: 2025-01-07T17:38:49.698Z

cve-icon NVD

Status : Deferred

Published: 2025-01-07T17:15:32.810

Modified: 2026-04-28T19:28:13.757

Link: CVE-2025-22319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T22:15:27Z

Weaknesses