Social Slider Feed <= 2.3.2 - Unauthenticated Stored Cross-Site Scripting
high
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...
- CVSS:
- 7.2
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 16, 2026
CVE-2026-39507 on NVD →
Social Slider Feed [instagram-slider-widget] < 2.2.9
unknown
[en] The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 2.2.9
- Fixed in:
- 2.2.9
- Disclosed:
- May 15, 2025
CVE-2024-10149 on NVD →
Social Slider Feed <= 2.2.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...
- CVSS:
- 4.4
- Affected:
- up to 2.2.8
- Fixed in:
- 2.2.9
- Disclosed:
- Mar 3, 2025
CVE-2025-0717 on NVD →
Social Slider Feed <= 2.2.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...
- CVSS:
- 4.4
- Affected:
- up to 2.2.8
- Fixed in:
- 2.2.9
- Disclosed:
- Feb 25, 2025
CVE-2024-10149 on NVD →
Social Slider Feed [instagram-slider-widget] < 2.2.5
unknown
[en] Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2.
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Nov 1, 2024
CVE-2024-43215 on NVD →
Social Slider Feed <= 2.2.2 - Missing Authorization
medium
The Social Slider Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.5
- Disclosed:
- Aug 9, 2024
CVE-2024-43215 on NVD →
Social Slider Feed <= 2.0.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hashtag parameter in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inj...
- CVSS:
- 5.5
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Aug 9, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.7
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Feeds discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.6).
Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.7).
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Aug 9, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.7
unknown
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hashtag parameter in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inj...
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Aug 9, 2022
Social Slider Feed <= 2.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via API key in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...
- CVSS:
- 5.5
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.6
- Disclosed:
- Aug 2, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.6
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability via API Key discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.5).
Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.6).
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Aug 2, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.6
unknown
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via API key in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Aug 2, 2022
Social Slider Feed <= 2.0.4 - Missing Authorization
high
The Social Slider Feed plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.4. This is due to missing capability checks and nonce validation on the 'showPageContent' function. This makes it possible for unauthenticated attackers to trigger feed deletion.
- CVSS:
- 8.8
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed <= 2.0.4 - Missing Authorization to Cross-Site Scripting
high
The Social Slider Feed plugin for WordPress is vulnerable to authenticated arbitrary API key update via the YouTube API key in versions up to, and including 2.0.4. This makes it possible for a subscriber-level attacker to change the API key. Proper sanitization is also missing allowing the attacker to inject malicious...
- CVSS:
- 7.2
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed <= 2.0.4 - Authenticated (Scubscriber+) Stored Cross-Site Scripting
medium
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permissions to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed <= 2.0.4 - Reflected Cross-Site Scripting
medium
The Social Slider Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permissions to inject arbitrary web scripts in pages that...
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
The Social Slider Feed plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.4. This is due to missing capability checks and nonce validation on the 'showPageContent' function. This makes it possible for unauthenticated attackers to trigger feed deletion.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
The Social Slider Feed plugin for WordPress is vulnerable to authenticated arbitrary API key update via the YouTube API key in versions up to, and including 2.0.4. This makes it possible for a subscriber-level attacker to change the API key. Proper sanitization is also missing allowing the attacker to inject malicious...
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
The Social Slider Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.4).
Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.5).
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Feeds discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.4).
Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.5).
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
Authenticated Arbitrary Feed Deletion vulnerability discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.4).
Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.5).
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
Authenticated Arbitrary API Key Update vulnerability leading to Stored Cross-Site Scripting (XSS) discovered by WPScan in WordPress Social Slider Feed plugin (versions <= 2.0.4).
Update the WordPress Social Slider Feed plugin to the latest available version (at least 2.0.5).
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 1, 2022
Social Slider Feed [instagram-slider-widget] < 1.8.5
unknown
[en] The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- Apr 5, 2021
CVE-2021-24196 on NVD →
Social Slider Widget <= 1.8.4 - Reflected Cross-Site Scripting
medium
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
- CVSS:
- 6.1
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- Mar 14, 2021
CVE-2021-24196 on NVD →
Social Slider Feed [instagram-slider-widget] < 2.0.7
unknown
The plugin does not sanitise as well as escape user input in feeds, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
Social Slider Feed [instagram-slider-widget] < 2.0.6
unknown
The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
The plugin does not have authorisation and CSRF check in place when saving the YouTube API Key, and does not sanitise as well as escape it. As a result, users with a role as low as subscriber could change it, including setting it with Stored Cross-Site Scripting payloads in it
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
The plugin does not have authorisation and CSRF check in place when deleting feeds, allowing ay authenticated users, such as subscriber to delete arbitrary feeds
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
Social Slider Feed [instagram-slider-widget] < 2.0.5
unknown
The plugin does not have authorisation and CSRF check in place when adding and editing a Feed, and does not sanitise as well as escape user input. As a result, users with a role as low as subscriber could add arbitrary feeds, with Stored Cross-Site Scripting payloads in them.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
Social Slider Feed [instagram-slider-widget] < 2.2.9
unknown
- Affected:
- up to 2.2.9
- Fixed in:
- 2.2.9
CVE-2025-0717 on NVD →