Flow-Flow Social Feed Stream [flow-flow-social-streams] <= 3.0.0 (unfixed)
unknown
[en] The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flow_flow_social_auth AJAX action in versions 3.0.0 to 4.7.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify plugi...
- Affected:
- up to 3.0.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 12, 2025
CVE-2025-13866 on NVD →
Flow-Flow Social Feed Stream 3.0.0 - 4.7.5 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via flow_flow_social_auth AJAX action
medium
The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the flow_flow_social_auth AJAX action in versions 3.0.0 to 4.7.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify plugin set...
- CVSS:
- 6.4
- Affected:
- 3.0.0 – 4.7.5
- Fixed in:
- 5.0.1
- Disclosed:
- Dec 11, 2025
CVE-2025-13866 on NVD →
Flow-Flow Social Feed Stream [flow-flow-social-streams] < 3.0.72
unknown
Unauthenticated Cross-Site Scripting (XSS) vulnerability found by Alaistair Jerrom-Smith in WordPress Flow-Flow Social Stream plugin (versions <= 3.0.71).
- Affected:
- up to 3.0.72
- Fixed in:
- 3.0.72
- Disclosed:
- Nov 13, 2018
Flow-Flow Social Feed Stream <= 3.0.71 - Cross-Site Scripting
medium
The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.0.71 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.0.72
- Fixed in:
- 3.0.72
- Disclosed:
- Nov 5, 2018
Flow-Flow Social Feed Stream [flow-flow-social-streams] < 3.0.72
unknown
The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.0.71 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 3.0.72
- Fixed in:
- 3.0.72
- Disclosed:
- Nov 5, 2018
Flow-Flow Social Feed Stream [flow-flow-social-streams] < 3.0.72
unknown
Cross-Site Scripting (XSS) vulnerability in the JSON output by modifying the hash parameter in admin-ajax.php using the fetch_posts action. Response Content-Type set to html.
- Affected:
- up to 3.0.72
- Fixed in:
- 3.0.72
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database