StreamWeasels Kick Integration <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via vodsChannel Parameter
medium
The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChannel’ parameter in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access a...
- CVSS:
- 6.4
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Sep 5, 2025
CVE-2025-9442 on NVD →
StreamWeasels Kick Integration <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...
- CVSS:
- 5.4
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.5
- Disclosed:
- Jul 28, 2025
CVE-2025-7810 on NVD →
StreamWeasels Kick Integration <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via status-classic-offline-text Parameter
medium
The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributo...
- CVSS:
- 6.4
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Jun 13, 2025
CVE-2025-5589 on NVD →
StreamWeasels Kick Integration [streamweasels-kick-integration] < 1.1.2
unknown
[en] The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-kick-embed shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Oct 29, 2024
CVE-2024-10184 on NVD →
SW Kick Integration - Blocks and Shortcodes for Embedding Kick Streams <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via sw-kick-embed Shortcode
medium
The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-kick-embed shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...
- CVSS:
- 6.4
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.2
- Disclosed:
- Oct 28, 2024
CVE-2024-10184 on NVD →
StreamWeasels Kick Integration [streamweasels-kick-integration] < 1.1.4
unknown
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
CVE-2025-5589 on NVD →
StreamWeasels Kick Integration [streamweasels-kick-integration] < 1.1.5
unknown
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
CVE-2025-7810 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database