FeedWordPress [feedwordpress] < 2024.0428
unknown
[en] The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticated attackers to view draft posts that may contain sensitive information.
- Affected:
- up to 2024.0428
- Fixed in:
- 2024.0428
- Disclosed:
- Mar 13, 2024
CVE-2024-0839 on NVD →
FeedWordPress <= 2022.0222 - Insecure Direct Object Referece
medium
The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticated attackers to view draft posts that may contain sensitive information.
- CVSS:
- 5.3
- Affected:
- up to 2022.0222
- Fixed in:
- 2024.0428
- Disclosed:
- Mar 4, 2024
CVE-2024-0839 on NVD →
FeedWordPress [feedwordpress] < 2022.0123
unknown
[en] The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
- Affected:
- up to 2022.0123
- Fixed in:
- 2022.0123
- Disclosed:
- Feb 21, 2022
CVE-2021-25055 on NVD →
FeedWordPress <= 2021.0713 - Reflected Cross-Site Scripting
medium
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
- CVSS:
- 6.1
- Affected:
- up to 2021.0713
- Fixed in:
- 2022.0123
- Disclosed:
- Jan 18, 2022
CVE-2021-25055 on NVD →
FeedWordPress [feedwordpress] < 2015.0514
unknown
[en] The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().
- Affected:
- up to 2015.0514
- Fixed in:
- 2015.0514
- Disclosed:
- Aug 28, 2019
CVE-2015-9358 on NVD →
FeedWordPress [feedwordpress] < 2015.0514
unknown
[en] SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-admin/admin.php.
- Affected:
- up to 2015.0514
- Fixed in:
- 2015.0514
- Disclosed:
- May 21, 2015
CVE-2015-4018 on NVD →
FeedWordPress < 2015.0514 - SQL Injection
critical
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-admin/admin.php.
- CVSS:
- 9.8
- Affected:
- up to 2015.0514
- Fixed in:
- 2015.0514
- Disclosed:
- May 19, 2015
CVE-2015-4018 on NVD →
FeedWordPress < 2015.0514 - Reflected Cross-Site Scripting
medium
The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().
- CVSS:
- 6.1
- Affected:
- up to 2015.0514
- Fixed in:
- 2015.0514
- Disclosed:
- May 14, 2015
CVE-2015-9358 on NVD →
FeedWordPress < 2015.0426 - Cross-Site Scripting
medium
The FeedWordPress plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 2015.0426 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 2014.0805
- Fixed in:
- 2015.0426
- Disclosed:
- Apr 26, 2015
FeedWordPress [feedwordpress] <= 2015.0426
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update this plugin.
- Affected:
- up to 2015.0426
- Fixed in:
- 2015.0426
- Disclosed:
- Apr 26, 2015
FeedWordPress [feedwordpress] < 2015.0426
unknown
The FeedWordPress plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 2015.0426 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2015.0426
- Fixed in:
- 2015.0426
- Disclosed:
- Apr 26, 2015
FeedWordPress [feedwordpress] < 2015.0426
unknown
The FeedWordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2015.0426
- Fixed in:
- 2015.0426
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database