plugin

Feed Them Social Vulnerabilities

29 known security issues reported for the Feed Them Social WordPress plugin. Most recent disclosed May 3, 2024.

3 critical 1 high 8 medium 1 low

Running Feed Them Social on your site? Check whether your installed version is affected.

Scan your site free

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 4.2.1

unknown

[en] Missing Authorization vulnerability in SlickRemix Feed Them Social.This issue affects Feed Them Social: from n/a through 4.2.0.

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
May 3, 2024

CVE-2024-24710 on NVD →

Feed Them Social <= 4.2.0 - Cross-Site Request Forgery via review_nag_check

low

The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.0. This is due to missing or incorrect nonce validation on the 'review_nag_check' function. This makes it possible for unauthenticated attackers to dis...

CVSS:
3.5
Affected:
up to 4.2.0
Fixed in:
4.2.1
Disclosed:
Jan 31, 2024

CVE-2024-24710 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.8.7

unknown

[en] The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the my_fts_fb_load_more() function. This makes it possible for unauthenticated attackers to...

Affected:
up to 2.8.7
Fixed in:
2.8.7
Disclosed:
Jul 1, 2023

CVE-2020-36739 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.8.7

unknown
Affected:
up to 2.8.7
Fixed in:
2.8.7
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 4.0.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in SlickRemix Feed Them Social plugin <= 3.0.2 versions.

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
May 23, 2023

CVE-2023-25056 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 4.0.8

unknown

Update the WordPress Feed Them Social plugin to the latest available version (at least 4.0.8). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Feed Them Social Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under...

Affected:
up to 4.0.8
Fixed in:
4.0.8
Disclosed:
Mar 30, 2023

Feed Them Social <= 4.0.7 - Cross-Site Request Forgery

medium

The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.7. This is due to missing or incorrect nonce validation on the save_meta_box function. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted the...

CVSS:
4.3
Affected:
up to 4.0.7
Fixed in:
4.0.8
Disclosed:
Mar 29, 2023

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 4.0.8

unknown

The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.7. This is due to missing or incorrect nonce validation on the save_meta_box function. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted the...

Affected:
up to 4.0.8
Fixed in:
4.0.8
Disclosed:
Mar 29, 2023

Feed Them Social <= 3.0.2 - Cross-Site Request Forgery

medium

The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.2. This is due to missing or incorrect nonce validation on the following functions: fts_maybe_set_transient, fts_check_nag_get, feed_them_settings, social_follow_button, fts_facebook_page_form, ft...

CVSS:
5.4
Affected:
up to 3.0.2
Fixed in:
4.0.0
Disclosed:
Feb 21, 2023

CVE-2023-25056 on NVD →

Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Cross-Site Request Forgery to Settings update

high

The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.9. This is due to missing or incorrect nonce validation on various functions such as fts_instagram_token_ajax(). This makes it possible for unauthenticated attackers to trigger settings updates vi...

CVSS:
8.8
Affected:
up to 2.9.9
Fixed in:
3.0.1
Disclosed:
Nov 14, 2022

CVE-2022-2942 on NVD →

Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Feed Them Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘access_token’ parameter in the function fts_instagram_token_ajax in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, subscri...

CVSS:
6.4
Affected:
up to 2.9.9
Fixed in:
3.0.1
Disclosed:
Nov 14, 2022

CVE-2022-2940 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 3.0.1

unknown

[en] The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Aug 22, 2022

CVE-2022-2383 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 3.0.1

unknown

[en] The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Aug 22, 2022

CVE-2022-2532 on NVD →

Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Reflected Cross-Site Scripting

medium

The Feed Them Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘access_token’ parameter in the function fts_refresh_token_ajax in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in...

CVSS:
6.1
Affected:
up to 2.9.9
Fixed in:
3.0.1
Disclosed:
Jul 26, 2022

CVE-2022-2383 on NVD →

Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Feed Them Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘access_token’ parameter in the function fts_encrypt_token_ajax in versions up to, and including, 2.9.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, subsc...

CVSS:
5.4
Affected:
up to 2.9.9
Fixed in:
3.0.1
Disclosed:
Jul 26, 2022

CVE-2022-2532 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.9.8.6

unknown

[en] The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the...

Affected:
up to 2.9.8.6
Fixed in:
2.9.8.6
Disclosed:
Jul 18, 2022

CVE-2022-2437 on NVD →

Feed Them Social – for Twitter feed, Youtube and more <= 2.9.8.5 - Cross-Site Request Forgery to Plugin Settings Update

critical

The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.8.5. This is due to missing or incorrect nonce validation on the fts_refresh_token_ajax function. This makes it possible for unauthenticated attackers to update plugin settings.

CVSS:
9.8
Affected:
up to 2.9.8.5
Fixed in:
2.9.8.6
Disclosed:
Jul 12, 2022

Feed Them Social – for Twitter feed, Youtube and more <= 2.9.8.5 - Unauthenticated PHAR Deserialization

critical

The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the data...

CVSS:
9.8
Affected:
up to 2.9.8.5
Fixed in:
2.9.8.6
Disclosed:
Jul 12, 2022

CVE-2022-2437 on NVD →

Feed Them Social – for Twitter feed, Youtube and more <= 2.9.9 - Reflected Cross-Site Scripting

medium

The Feed Them Social plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘expires_in’ parameter in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 2.9.9
Fixed in:
3.0.1
Disclosed:
Jul 12, 2022

CVE-2022-2383 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.9.8.6

unknown

The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.8.5. This is due to missing or incorrect nonce validation on the fts_refresh_token_ajax function. This makes it possible for unauthenticated attackers to update plugin settings.

Affected:
up to 2.9.8.6
Fixed in:
2.9.8.6
Disclosed:
Jul 12, 2022

Feed Them Social – Page, Post, Video, and Photo Galleries <= 2.8.6 - Cross-Site Request Forgery Bypass

medium

The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the my_fts_fb_load_more() function. This makes it possible for unauthenticated attackers to load...

CVSS:
4.3
Affected:
up to 2.8.7
Fixed in:
2.8.7
Disclosed:
Sep 16, 2020

CVE-2020-36739 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.8.7

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Feed Them Social plugin (versions <= 2.8.6).

Affected:
up to 2.8.7
Fixed in:
2.8.7
Disclosed:
Sep 16, 2020

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 1.7.0

unknown

[en] The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Aug 27, 2019

CVE-2015-9350 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 1.7.0

unknown

[en] The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Aug 27, 2019

CVE-2015-9351 on NVD →

Feed Them Social <= 1.6.9 - Arbitrary Shortcode Execution

critical

The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.

CVSS:
9.8
Affected:
up to 1.6.9
Fixed in:
1.7.0
Disclosed:
Feb 2, 2015

CVE-2015-9351 on NVD →

Feed Them Social <= 1.6.9 - Reflected Cross-Site Scripting

medium

The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.

CVSS:
6.1
Affected:
up to 1.6.9
Fixed in:
1.7.0
Disclosed:
Feb 2, 2015

CVE-2015-9350 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 3.0.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.0.1
Fixed in:
3.0.1

CVE-2022-2940 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 3.0.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.0.1
Fixed in:
3.0.1

CVE-2022-2942 on NVD →

Feed Them Social &#8211; Social Media Feeds, Video, and Photo Galleries [feed-them-social] < 2.8.7

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 2.8.7
Fixed in:
2.8.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database