Extension WordPress
Vulnérabilités Custom Twitter Feeds – A Tweets Widget or X Feed Widget
Cette page rassemble les failles publiées pour Custom Twitter Feeds – A Tweets Widget or X Feed Widget, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Custom Twitter Feeds – A Tweets Widget or X Feed Widget
8 fiches
Custom Twitter Feeds <= 2.5.4 – Unauthenticated Stored Cross-Site Scripting via Cached Tweet Text
The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's…
*-2.5.4
2.5.5
12/05/2026
Custom Twitter Feeds <= 2.2.5 – Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or incorrect nonce validation…
*-2.2.5
2.3.0
19/03/2025
Custom Twitter Feeds (Tweets Widget) <= 2.2.3 – Cross-Site Request Forgery
The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.3. This is due to missing or incorrect nonce validation on a function. This makes it possible…
*-2.2.3
2.2.4
21/10/2024
Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.2 due to insufficient input sanitization and…
*-2.2.2
2.2.3
17/09/2024
Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 – Cross-Site Request Forgery to Plugin Options Update
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation…
*-2.2.1
2.2.2
06/02/2024
Custom Twitter Feeds (Tweets Widget) <= 2.1.2 – Cross-Site Request Forgery
The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it…
*-2.1.2
2.2
28/12/2023
Custom Twitter Feeds (Tweets Widget) <= 1.8.4 – Cross-Site Request Forgery
The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers…
[*, 2.0)
2.0
25/05/2023
Smash Balloon Plugins (Various Versions) – Reflected Cross-Site Scripting
Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to…
*-1.8.1
1.8.2
20/07/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.