Fancy Comments WordPress [fancy-facebook-comments] < 1.2.15
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows Stored XSS.This issue affects Fancy Comments WordPress: from n/a through 1.2.14.
- Affected:
- up to 1.2.15
- Fixed in:
- 1.2.15
- Disclosed:
- Mar 27, 2024
CVE-2024-29804 on NVD →
Fancy Comments WordPress <= 1.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Fancy Comments WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's facebook_comments_shortcode shortcode function in all versions up to, and including, 1.2.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a...
- CVSS:
- 6.4
- Affected:
- up to 1.2.14
- Fixed in:
- 1.2.15
- Disclosed:
- Mar 25, 2024
CVE-2024-29804 on NVD →
Fancy Comments WordPress [fancy-facebook-comments] < 1.2.11
unknown
[en] Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions.
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.11
- Disclosed:
- Mar 30, 2023
CVE-2023-23670 on NVD →
WordPress Fancy Comments <= 1.2.10 - Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode
medium
WordPress Fancy Comments Plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.10 due to insufficient input sanitization and output escaping on user supplied attributes passed to the plugin's shortcodes. This makes it possible for authenticated attackers, with contribut...
- CVSS:
- 6.4
- Affected:
- up to 1.2.10
- Fixed in:
- 1.2.11
- Disclosed:
- Feb 13, 2023
CVE-2023-23670 on NVD →
Fancy Comments WordPress [fancy-facebook-comments] < 1.2.15
unknown
The plugin does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin
- Affected:
- up to 1.2.15
- Fixed in:
- 1.2.15
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database