flickrRSS [flickr-rss] < 5.3.2 (closed)
unknownMultiple Cross-Site Scripting (XSS) vulnerabilities found by AntsKnows in WordPress flickrRSS plugin (versions <= 5.3.1).
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- Feb 7, 2018
plugin
9 known security issues reported for the Flickr Rss WordPress plugin. Most recent disclosed Feb 7, 2018.
Running Flickr Rss on your site? Check whether your installed version is affected.
Scan your site freeMultiple Cross-Site Scripting (XSS) vulnerabilities found by AntsKnows in WordPress flickrRSS plugin (versions <= 5.3.1).
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_id parameter to wp-admin/options-general.php.
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_set parameter to wp-admin/options-general.php.
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_tags parameter to wp-admin/options-general.php.
The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php. This makes it possible for unauthenticated attackers to change plugin settings via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
[en] The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php.
[en] A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_id parameter to wp-admin/options-general.php.
[en] A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_set parameter to wp-admin/options-general.php.
[en] A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_tags parameter to wp-admin/options-general.php.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free