BestWebSoft's Twitter [twitter-plugin] < 1.3.7
unknown
[en] A vulnerability was found in BestWebSoft Twitter Plugin up to 1.3.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function twttr_settings_page of the file twitter.php. The manipulation of the argument twttr_url_twitter/bws_license_key/bws_license_plugin leads to cross sit...
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- May 31, 2023
CVE-2014-125103 on NVD →
BestWebSoft's Twitter [twitter-plugin] < 2.15
unknown
[en] A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twttr_settings_page of the file twitter.php of the component Settings Page. The manipulation leads to cross-site request forgery. It is possible to launch the attack remo...
- Affected:
- up to 2.15
- Fixed in:
- 2.15
- Disclosed:
- May 30, 2023
CVE-2012-10015 on NVD →
BestWebSoft's Twitter [twitter-plugin] < 2.55
unknown
[en] The twitter-plugin plugin before 2.55 for WordPress has XSS.
- Affected:
- up to 2.55
- Fixed in:
- 2.55
- Disclosed:
- Aug 12, 2019
CVE-2017-18505 on NVD →
BestWebSoft's Twitter [twitter-plugin] < 2.55
unknown
[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,...
- Affected:
- up to 2.55
- Fixed in:
- 2.55
- Disclosed:
- May 22, 2017
CVE-2017-2171 on NVD →
BestWebSoft's Twitter < 2.55 - Cross-Site Scripting
medium
The BestWebSoft's Twitter plugin before 2.55 for WordPress has XSS via several parameters.
- CVSS:
- 6.1
- Affected:
- up to 2.55
- Fixed in:
- 2.55
- Disclosed:
- Apr 12, 2017
CVE-2017-18505 on NVD →
BestWebSoft's Twitter <= 1.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The BestWebSoft's Twitter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inje...
- CVSS:
- 4.4
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.7
- Disclosed:
- Aug 7, 2014
CVE-2014-125103 on NVD →
BestWebSoft's Twitter <= 2.14 - Cross-Site Request Forgery
medium
The BestWebSoft's Twitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14. This is due to missing nonce validation on the twttr_settings_page() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request gran...
- CVSS:
- 4.3
- Affected:
- up to 2.14
- Fixed in:
- 2.15
- Disclosed:
- Jul 24, 2012
CVE-2012-10015 on NVD →
BestWebSoft's Twitter [twitter-plugin] < 2.55
unknown
- Affected:
- up to 2.55
- Fixed in:
- 2.55
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database