Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown
CVE-2022-33974
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.
0
Attacker Value
Unknown
CVE-2021-24413
Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
0
Attacker Value
Unknown
CVE-2010-4825
Disclosure Date: August 24, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in magpie_debug.php in the Twitter Feed plugin (wp-twitter-feed) 0.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
0