Extension WordPress

Vulnérabilités Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Cette page rassemble les failles publiées pour Custom Twitter Feeds – A Tweets Widget or X Feed Widget, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Custom Twitter Feeds – A Tweets Widget or X Feed Widget

8 fiches

CVE-2026-6177 Élevée · 7,2
Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Custom Twitter Feeds <= 2.5.4 – Unauthenticated Stored Cross-Site Scripting via Cached Tweet Text

The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's…

Versions affectées

*-2.5.4

Correctif

2.5.5

Publication

12/05/2026

CVE-2025-1314 Moyenne · 4,3
Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Custom Twitter Feeds <= 2.2.5 – Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or incorrect nonce validation…

Versions affectées

*-2.2.5

Correctif

2.3.0

Publication

19/03/2025

CVE-2024-49685 Moyenne · 4,3
Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Custom Twitter Feeds (Tweets Widget) <= 2.2.3 – Cross-Site Request Forgery

The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.3. This is due to missing or incorrect nonce validation on a function. This makes it possible…

Versions affectées

*-2.2.3

Correctif

2.2.4

Publication

21/10/2024

CVE-2024-8983 Moyenne · 4,8
Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.2 – Authenticated (Admin+) Stored Cross-Site Scripting

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.2 due to insufficient input sanitization and…

Versions affectées

*-2.2.2

Correctif

2.2.3

Publication

17/09/2024

CVE-2024-0379 Moyenne · 4,3
Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 – Cross-Site Request Forgery to Plugin Options Update

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

06/02/2024

CVE-2022-33974 Moyenne · 4,3
Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Custom Twitter Feeds (Tweets Widget) <= 1.8.4 – Cross-Site Request Forgery

The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers…

Versions affectées

[*, 2.0)

Correctif

2.0

Publication

25/05/2023

Vulnérabilité Moyenne · 6,1
Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Smash Balloon Plugins (Various Versions) – Reflected Cross-Site Scripting

Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to…

Versions affectées

*-1.8.1

Correctif

1.8.2

Publication

20/07/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités