Easy Social Feed < 6.2.7 - Reflected Cross-Site Scripting
CVE-2021-25120

6.1MEDIUM

Key Information:

Summary

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

Affected Version(s)

Easy Social Feed – Social Photos Gallery – Post Feed – Like Box 6.2.7

Easy Social Feed Pro 6.2.7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thura Moe Myint
.