Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 4.2.1
unknown
[en] Missing Authorization vulnerability in SlickRemix Feed Them Social.This issue affects Feed Them Social: from n/a through 4.2.0.
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.1
- Disclosed:
- May 3, 2024
CVE-2024-24710 on NVD →
Feed Them Social <= 4.2.0 - Cross-Site Request Forgery via review_nag_check
low
The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.0. This is due to missing or incorrect nonce validation on the 'review_nag_check' function. This makes it possible for unauthenticated attackers to dis...
- CVSS:
- 3.5
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.1
- Disclosed:
- Jan 31, 2024
CVE-2024-24710 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.8.7
unknown
[en] The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the my_fts_fb_load_more() function. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Jul 1, 2023
CVE-2020-36739 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.8.7
unknown
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 4.0.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in SlickRemix Feed Them Social plugin <= 3.0.2 versions.
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- May 23, 2023
CVE-2023-25056 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 4.0.8
unknown
Update the WordPress Feed Them Social plugin to the latest available version (at least 4.0.8).
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Feed Them Social Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under...
- Affected:
- up to 4.0.8
- Fixed in:
- 4.0.8
- Disclosed:
- Mar 30, 2023
Feed Them Social <= 4.0.7 - Cross-Site Request Forgery
medium
The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.7. This is due to missing or incorrect nonce validation on the save_meta_box function. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted the...
- CVSS:
- 4.3
- Affected:
- up to 4.0.7
- Fixed in:
- 4.0.8
- Disclosed:
- Mar 29, 2023
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 4.0.8
unknown
The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.7. This is due to missing or incorrect nonce validation on the save_meta_box function. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted the...
- Affected:
- up to 4.0.8
- Fixed in:
- 4.0.8
- Disclosed:
- Mar 29, 2023
Feed Them Social <= 3.0.2 - Cross-Site Request Forgery
medium
The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.2. This is due to missing or incorrect nonce validation on the following functions: fts_maybe_set_transient, fts_check_nag_get, feed_them_settings, social_follow_button, fts_facebook_page_form, ft...
- CVSS:
- 5.4
- Affected:
- up to 3.0.2
- Fixed in:
- 4.0.0
- Disclosed:
- Feb 21, 2023
CVE-2023-25056 on NVD →
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Cross-Site Request Forgery to Settings update
high
The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.9. This is due to missing or incorrect nonce validation on various functions such as fts_instagram_token_ajax(). This makes it possible for unauthenticated attackers to trigger settings updates vi...
- CVSS:
- 8.8
- Affected:
- up to 2.9.9
- Fixed in:
- 3.0.1
- Disclosed:
- Nov 14, 2022
CVE-2022-2942 on NVD →
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Feed Them Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘access_token’ parameter in the function fts_instagram_token_ajax in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, subscri...
- CVSS:
- 6.4
- Affected:
- up to 2.9.9
- Fixed in:
- 3.0.1
- Disclosed:
- Nov 14, 2022
CVE-2022-2940 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 3.0.1
unknown
[en] The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Aug 22, 2022
CVE-2022-2383 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 3.0.1
unknown
[en] The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Aug 22, 2022
CVE-2022-2532 on NVD →
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Reflected Cross-Site Scripting
medium
The Feed Them Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘access_token’ parameter in the function fts_refresh_token_ajax in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in...
- CVSS:
- 6.1
- Affected:
- up to 2.9.9
- Fixed in:
- 3.0.1
- Disclosed:
- Jul 26, 2022
CVE-2022-2383 on NVD →
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Feed Them Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘access_token’ parameter in the function fts_encrypt_token_ajax in versions up to, and including, 2.9.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, subsc...
- CVSS:
- 5.4
- Affected:
- up to 2.9.9
- Fixed in:
- 3.0.1
- Disclosed:
- Jul 26, 2022
CVE-2022-2532 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.9.8.6
unknown
[en] The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the...
- Affected:
- up to 2.9.8.6
- Fixed in:
- 2.9.8.6
- Disclosed:
- Jul 18, 2022
CVE-2022-2437 on NVD →
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.8.5 - Cross-Site Request Forgery to Plugin Settings Update
critical
The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.8.5. This is due to missing or incorrect nonce validation on the fts_refresh_token_ajax function. This makes it possible for unauthenticated attackers to update plugin settings.
- CVSS:
- 9.8
- Affected:
- up to 2.9.8.5
- Fixed in:
- 2.9.8.6
- Disclosed:
- Jul 12, 2022
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.8.5 - Unauthenticated PHAR Deserialization
critical
The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the data...
- CVSS:
- 9.8
- Affected:
- up to 2.9.8.5
- Fixed in:
- 2.9.8.6
- Disclosed:
- Jul 12, 2022
CVE-2022-2437 on NVD →
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Reflected Cross-Site Scripting
medium
The Feed Them Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘expires_in’ parameter in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 2.9.9
- Fixed in:
- 3.0.1
- Disclosed:
- Jul 12, 2022
CVE-2022-2383 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.9.8.6
unknown
The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.8.5. This is due to missing or incorrect nonce validation on the fts_refresh_token_ajax function. This makes it possible for unauthenticated attackers to update plugin settings.
- Affected:
- up to 2.9.8.6
- Fixed in:
- 2.9.8.6
- Disclosed:
- Jul 12, 2022
Feed Them Social – Page, Post, Video, and Photo Galleries <= 2.8.6 - Cross-Site Request Forgery Bypass
medium
The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the my_fts_fb_load_more() function. This makes it possible for unauthenticated attackers to load...
- CVSS:
- 4.3
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Sep 16, 2020
CVE-2020-36739 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.8.7
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Feed Them Social plugin (versions <= 2.8.6).
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Sep 16, 2020
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 1.7.0
unknown
[en] The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Aug 27, 2019
CVE-2015-9350 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 1.7.0
unknown
[en] The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Aug 27, 2019
CVE-2015-9351 on NVD →
Feed Them Social <= 1.6.9 - Arbitrary Shortcode Execution
critical
The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.
- CVSS:
- 9.8
- Affected:
- up to 1.6.9
- Fixed in:
- 1.7.0
- Disclosed:
- Feb 2, 2015
CVE-2015-9351 on NVD →
Feed Them Social <= 1.6.9 - Reflected Cross-Site Scripting
medium
The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.
- CVSS:
- 6.1
- Affected:
- up to 1.6.9
- Fixed in:
- 1.7.0
- Disclosed:
- Feb 2, 2015
CVE-2015-9350 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 3.0.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
CVE-2022-2940 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 3.0.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
CVE-2022-2942 on NVD →
Feed Them Social – Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.8.7
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7