Custom Twitter Feeds <= 2.5.4 - Unauthenticated Stored Cross-Site Scripting via Cached Tweet Text
high
The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts AJAX action is available t...
- CVSS:
- 7.2
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.5
- Disclosed:
- May 12, 2026
CVE-2026-6177 on NVD →
Custom Twitter Feeds <= 2.2.5 - Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function
medium
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or incorrect nonce validation on the ctf_clear_cache_admin() function. This makes it possible for unauthenticated attackers to...
- CVSS:
- 4.3
- Affected:
- up to 2.2.5
- Fixed in:
- 2.3.0
- Disclosed:
- Mar 19, 2025
CVE-2025-1314 on NVD →
Custom Twitter Feeds – A Tweets Widget or X Feed Widget [custom-twitter-feeds] < 2.2.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets Widget): from n/a through 2.2.3.
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.4
- Disclosed:
- Oct 31, 2024
CVE-2024-49685 on NVD →
Custom Twitter Feeds (Tweets Widget) <= 2.2.3 - Cross-Site Request Forgery
medium
The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged reque...
- CVSS:
- 4.3
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.4
- Disclosed:
- Oct 21, 2024
CVE-2024-49685 on NVD →
Custom Twitter Feeds – A Tweets Widget or X Feed Widget [custom-twitter-feeds] < 2.2.3
unknown
[en] Custom Twitter Feeds WordPress plugin before 2.2.3 is not filtering some of its settings allowing high privilege users to inject scripts.
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Oct 8, 2024
CVE-2024-8983 on NVD →
Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.8
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Sep 17, 2024
CVE-2024-8983 on NVD →
Custom Twitter Feeds – A Tweets Widget or X Feed Widget [custom-twitter-feeds] < 2.2.2
unknown
[en] The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers t...
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Feb 20, 2024
CVE-2024-0379 on NVD →
Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Update
medium
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers to upd...
- CVSS:
- 4.3
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Feb 6, 2024
CVE-2024-0379 on NVD →
Custom Twitter Feeds – A Tweets Widget or X Feed Widget [custom-twitter-feeds] < 2.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget or X Feed Widget: from n/a through 2.1.2.
- Affected:
- up to 2.2
- Fixed in:
- 2.2
- Disclosed:
- Jan 5, 2024
CVE-2023-52136 on NVD →
Custom Twitter Feeds (Tweets Widget) <= 2.1.2 - Cross-Site Request Forgery
medium
The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a for...
- CVSS:
- 4.3
- Affected:
- up to 2.1.2
- Fixed in:
- 2.2
- Disclosed:
- Dec 28, 2023
CVE-2023-52136 on NVD →
Custom Twitter Feeds – A Tweets Widget or X Feed Widget [custom-twitter-feeds] < 2.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- May 29, 2023
CVE-2022-33974 on NVD →
Custom Twitter Feeds (Tweets Widget) <= 1.8.4 - Cross-Site Request Forgery
medium
The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- May 25, 2023
CVE-2022-33974 on NVD →
Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting
medium
Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- CVSS:
- 6.1
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Jul 20, 2021
Custom Twitter Feeds – A Tweets Widget or X Feed Widget [custom-twitter-feeds] < 1.8.2
unknown
Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Jul 20, 2021
Custom Twitter Feeds – A Tweets Widget or X Feed Widget [custom-twitter-feeds] < 2.3.0
unknown
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
CVE-2025-1314 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database