plugin

Feedwordpress Vulnerabilities

12 known security issues reported for the Feedwordpress WordPress plugin. Most recent disclosed Mar 13, 2024.

1 critical 4 medium

Running Feedwordpress on your site? Check whether your installed version is affected.

Scan your site free

FeedWordPress [feedwordpress] < 2024.0428

unknown

[en] The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticated attackers to view draft posts that may contain sensitive information.

Affected:
up to 2024.0428
Fixed in:
2024.0428
Disclosed:
Mar 13, 2024

CVE-2024-0839 on NVD →

FeedWordPress <= 2022.0222 - Insecure Direct Object Referece

medium

The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticated attackers to view draft posts that may contain sensitive information.

CVSS:
5.3
Affected:
up to 2022.0222
Fixed in:
2024.0428
Disclosed:
Mar 4, 2024

CVE-2024-0839 on NVD →

FeedWordPress [feedwordpress] < 2022.0123

unknown

[en] The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.

Affected:
up to 2022.0123
Fixed in:
2022.0123
Disclosed:
Feb 21, 2022

CVE-2021-25055 on NVD →

FeedWordPress <= 2021.0713 - Reflected Cross-Site Scripting

medium

The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.

CVSS:
6.1
Affected:
up to 2021.0713
Fixed in:
2022.0123
Disclosed:
Jan 18, 2022

CVE-2021-25055 on NVD →

FeedWordPress [feedwordpress] < 2015.0514

unknown

[en] The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().

Affected:
up to 2015.0514
Fixed in:
2015.0514
Disclosed:
Aug 28, 2019

CVE-2015-9358 on NVD →

FeedWordPress [feedwordpress] < 2015.0514

unknown

[en] SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-admin/admin.php.

Affected:
up to 2015.0514
Fixed in:
2015.0514
Disclosed:
May 21, 2015

CVE-2015-4018 on NVD →

FeedWordPress < 2015.0514 - SQL Injection

critical

SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-admin/admin.php.

CVSS:
9.8
Affected:
up to 2015.0514
Fixed in:
2015.0514
Disclosed:
May 19, 2015

CVE-2015-4018 on NVD →

FeedWordPress < 2015.0514 - Reflected Cross-Site Scripting

medium

The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVSS:
6.1
Affected:
up to 2015.0514
Fixed in:
2015.0514
Disclosed:
May 14, 2015

CVE-2015-9358 on NVD →

FeedWordPress < 2015.0426 - Cross-Site Scripting

medium

The FeedWordPress plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 2015.0426 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 2014.0805
Fixed in:
2015.0426
Disclosed:
Apr 26, 2015

FeedWordPress [feedwordpress] <= 2015.0426

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update this plugin.

Affected:
up to 2015.0426
Fixed in:
2015.0426
Disclosed:
Apr 26, 2015

FeedWordPress [feedwordpress] < 2015.0426

unknown

The FeedWordPress plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 2015.0426 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2015.0426
Fixed in:
2015.0426
Disclosed:
Apr 26, 2015

FeedWordPress [feedwordpress] < 2015.0426

unknown

The FeedWordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2015.0426
Fixed in:
2015.0426

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database