Sensitive Information Exposure in ShareThis Dashboard for Google Analytics Plugin
CVE-2025-12540
4.7MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 January 2026
What is CVE-2025-12540?
The ShareThis Dashboard for Google Analytics plugin for WordPress exhibits a serious vulnerability that allows for sensitive information exposure. In all versions up to and including 3.2.4, the plugin stores critical credentials such as client_ID and client_secret in plaintext within its openly accessible source code. This flaw can enable unauthenticated attackers to exploit the vulnerability by creating links to the sharethis.com server. If a logged-in administrator inadvertently clicks such a link, an authorization token for Google Analytics may be shared with a malicious third-party site, potentially leading to unauthorized access to sensitive analytics data.
Affected Version(s)
ShareThis Dashboard for Google Analytics 0 <= 3.2.4