CVE-2025-12540

T

he ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.4. This is due to the Google Analytics client_ID and client_secret being stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to craft a link to the sharethis.com server, which will share an authorization token for Google Analytics with a malicious website, if the attacker can trick an administrator logged into the website and Google Analytics to click the link.

Configurations

No configuration.

History

07 Jan 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-07 12:16

Updated : 2026-01-08 18:09


NVD link : CVE-2025-12540

Mitre link : CVE-2025-12540

CVE.ORG link : CVE-2025-12540


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor