plugin

Instagram Slider Widget Vulnerabilities

33 known security issues reported for the Instagram Slider Widget WordPress plugin. Most recent disclosed Apr 16, 2026.

3 high 8 medium

Running Instagram Slider Widget on your site? Check whether your installed version is affected.

Scan your site free

Social Slider Feed <= 2.3.2 - Unauthenticated Stored Cross-Site Scripting

high

The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...

CVSS:
7.2
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Apr 16, 2026

CVE-2026-39507 on NVD →

Social Slider Feed [instagram-slider-widget] < 2.2.9

unknown

[en] The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
May 15, 2025

CVE-2024-10149 on NVD →

Social Slider Feed <= 2.2.8 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...

CVSS:
4.4
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Mar 3, 2025

CVE-2025-0717 on NVD →

Social Slider Feed <= 2.2.8 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...

CVSS:
4.4
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Feb 25, 2025

CVE-2024-10149 on NVD →

Social Slider Feed [instagram-slider-widget] < 2.2.5

unknown

[en] Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2.

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Nov 1, 2024

CVE-2024-43215 on NVD →

Social Slider Feed <= 2.2.2 - Missing Authorization

medium

The Social Slider Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.2.2
Fixed in:
2.2.5
Disclosed:
Aug 9, 2024

CVE-2024-43215 on NVD →

Social Slider Feed <= 2.0.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hashtag parameter in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inj...

CVSS:
5.5
Affected:
up to 2.0.6
Fixed in:
2.0.7
Disclosed:
Aug 9, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.7

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Feeds discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.6). Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.7).

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Aug 9, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.7

unknown

The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hashtag parameter in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inj...

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Aug 9, 2022

Social Slider Feed <= 2.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via API key in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...

CVSS:
5.5
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Aug 2, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.6

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability via API Key discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.5). Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.6).

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Aug 2, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.6

unknown

The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via API key in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Aug 2, 2022

Social Slider Feed <= 2.0.4 - Missing Authorization

high

The Social Slider Feed plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.4. This is due to missing capability checks and nonce validation on the 'showPageContent' function. This makes it possible for unauthenticated attackers to trigger feed deletion.

CVSS:
8.8
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed <= 2.0.4 - Missing Authorization to Cross-Site Scripting

high

The Social Slider Feed plugin for WordPress is vulnerable to authenticated arbitrary API key update via the YouTube API key in versions up to, and including 2.0.4. This makes it possible for a subscriber-level attacker to change the API key. Proper sanitization is also missing allowing the attacker to inject malicious...

CVSS:
7.2
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed <= 2.0.4 - Authenticated (Scubscriber+) Stored Cross-Site Scripting

medium

The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permissions to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed <= 2.0.4 - Reflected Cross-Site Scripting

medium

The Social Slider Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permissions to inject arbitrary web scripts in pages that...

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

The Social Slider Feed plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.4. This is due to missing capability checks and nonce validation on the 'showPageContent' function. This makes it possible for unauthenticated attackers to trigger feed deletion.

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

The Social Slider Feed plugin for WordPress is vulnerable to authenticated arbitrary API key update via the YouTube API key in versions up to, and including 2.0.4. This makes it possible for a subscriber-level attacker to change the API key. Proper sanitization is also missing allowing the attacker to inject malicious...

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

The Social Slider Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.4). Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.5).

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Feeds discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.4). Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.5).

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

Authenticated Arbitrary Feed Deletion vulnerability discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.4). Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.5).

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

Authenticated Arbitrary API Key Update vulnerability leading to Stored Cross-Site Scripting (XSS) discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.4). Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.5).

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Aug 1, 2022

Social Slider Feed [instagram-slider-widget] < 1.8.5

unknown

[en] The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized

Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
Apr 5, 2021

CVE-2021-24196 on NVD →

Social Slider Widget <= 1.8.4 - Reflected Cross-Site Scripting

medium

The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized

CVSS:
6.1
Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
Mar 14, 2021

CVE-2021-24196 on NVD →

Social Slider Feed [instagram-slider-widget] < 2.0.7

unknown

The plugin does not sanitise as well as escape user input in feeds, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.0.7
Fixed in:
2.0.7

Social Slider Feed [instagram-slider-widget] < 2.0.6

unknown

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.0.6
Fixed in:
2.0.6

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 2.0.5
Fixed in:
2.0.5

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

The plugin does not have authorisation and CSRF check in place when saving the YouTube API Key, and does not sanitise as well as escape it. As a result, users with a role as low as subscriber could change it, including setting it with Stored Cross-Site Scripting payloads in it

Affected:
up to 2.0.5
Fixed in:
2.0.5

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

The plugin does not have authorisation and CSRF check in place when deleting feeds, allowing ay authenticated users, such as subscriber to delete arbitrary feeds

Affected:
up to 2.0.5
Fixed in:
2.0.5

Social Slider Feed [instagram-slider-widget] < 2.0.5

unknown

The plugin does not have authorisation and CSRF check in place when adding and editing a Feed, and does not sanitise as well as escape user input. As a result, users with a role as low as subscriber could add arbitrary feeds, with Stored Cross-Site Scripting payloads in them.

Affected:
up to 2.0.5
Fixed in:
2.0.5

Social Slider Feed [instagram-slider-widget] < 2.2.9

unknown
Affected:
up to 2.2.9
Fixed in:
2.2.9

CVE-2025-0717 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database