plugin

Streamweasels Kick Integration Vulnerabilities

7 known security issues reported for the Streamweasels Kick Integration WordPress plugin. Most recent disclosed Sep 5, 2025.

4 medium

Running Streamweasels Kick Integration on your site? Check whether your installed version is affected.

Scan your site free

StreamWeasels Kick Integration <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via vodsChannel Parameter

medium

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChannel’ parameter in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access a...

CVSS:
6.4
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Sep 5, 2025

CVE-2025-9442 on NVD →

StreamWeasels Kick Integration <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...

CVSS:
5.4
Affected:
up to 1.1.4
Fixed in:
1.1.5
Disclosed:
Jul 28, 2025

CVE-2025-7810 on NVD →

StreamWeasels Kick Integration <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via status-classic-offline-text Parameter

medium

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributo...

CVSS:
6.4
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Jun 13, 2025

CVE-2025-5589 on NVD →

StreamWeasels Kick Integration [streamweasels-kick-integration] < 1.1.2

unknown

[en] The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-kick-embed shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Oct 29, 2024

CVE-2024-10184 on NVD →

SW Kick Integration - Blocks and Shortcodes for Embedding Kick Streams <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via sw-kick-embed Shortcode

medium

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-kick-embed shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...

CVSS:
6.4
Affected:
up to 1.1.1
Fixed in:
1.1.2
Disclosed:
Oct 28, 2024

CVE-2024-10184 on NVD →

StreamWeasels Kick Integration [streamweasels-kick-integration] < 1.1.4

unknown
Affected:
up to 1.1.4
Fixed in:
1.1.4

CVE-2025-5589 on NVD →

StreamWeasels Kick Integration [streamweasels-kick-integration] < 1.1.5

unknown
Affected:
up to 1.1.5
Fixed in:
1.1.5

CVE-2025-7810 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database