10Web Social Photo Feed <= 1.4.28 - Reflected Cross-Site Scripting
medium
The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users
- CVSS:
- 6.1
- Affected:
- up to 1.4.28
- Fixed in:
- 1.4.29
- Disclosed:
- Dec 7, 2021
CVE-2021-25047 on NVD →
WD Instagram Feed <= 1.3.0 - Cross-site scripting
medium
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's bio.
- CVSS:
- 6.1
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Apr 23, 2018
CVE-2018-10300 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database