The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to a type of cyberattack called Stored Cross-Site Scripting. This type of attack is possible in versions before 1.1.1.12 due to a lack of proper security measures. If exploited, it would allow a malicious user with a low-level of access to inject malicious web scripts into pages, which would then run whenever someone views those pages.