plugin

Fancy Facebook Comments Vulnerabilities

5 known security issues reported for the Fancy Facebook Comments WordPress plugin. Most recent disclosed Mar 27, 2024.

2 medium

Running Fancy Facebook Comments on your site? Check whether your installed version is affected.

Scan your site free

Fancy Comments WordPress [fancy-facebook-comments] < 1.2.15

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows Stored XSS.This issue affects Fancy Comments WordPress: from n/a through 1.2.14.

Affected:
up to 1.2.15
Fixed in:
1.2.15
Disclosed:
Mar 27, 2024

CVE-2024-29804 on NVD →

Fancy Comments WordPress <= 1.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Fancy Comments WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's facebook_comments_shortcode shortcode function in all versions up to, and including, 1.2.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a...

CVSS:
6.4
Affected:
up to 1.2.14
Fixed in:
1.2.15
Disclosed:
Mar 25, 2024

CVE-2024-29804 on NVD →

Fancy Comments WordPress [fancy-facebook-comments] < 1.2.11

unknown

[en] Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions.

Affected:
up to 1.2.11
Fixed in:
1.2.11
Disclosed:
Mar 30, 2023

CVE-2023-23670 on NVD →

WordPress Fancy Comments <= 1.2.10 - Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode

medium

WordPress Fancy Comments Plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.10 due to insufficient input sanitization and output escaping on user supplied attributes passed to the plugin's shortcodes. This makes it possible for authenticated attackers, with contribut...

CVSS:
6.4
Affected:
up to 1.2.10
Fixed in:
1.2.11
Disclosed:
Feb 13, 2023

CVE-2023-23670 on NVD →

Fancy Comments WordPress [fancy-facebook-comments] < 1.2.15

unknown

The plugin does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

Affected:
up to 1.2.15
Fixed in:
1.2.15

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database