Extension WordPress
Vulnérabilités Social Slider Feed – Social Media Feed & Gallery Widgets
Cette page rassemble les failles publiées pour Social Slider Feed – Social Media Feed & Gallery Widgets, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Social Slider Feed – Social Media Feed & Gallery Widgets
11 fiches
Social Slider Feed <= 2.3.2 – Unauthenticated Stored Cross-Site Scripting
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-2.3.2
2.3.3
16/04/2026
Social Slider Feed <= 2.2.8 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.2.8
2.2.9
03/03/2025
Social Slider Feed <= 2.2.8 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.2.8
2.2.9
25/02/2025
Social Slider Feed <= 2.2.2 – Missing Authorization
The Social Slider Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to perform…
*-2.2.2
2.2.5
09/08/2024
Social Slider Feed <= 2.0.6 – Authenticated (Admin+) Stored Cross-Site Scripting
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hashtag parameter in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.0.6
2.0.7
09/08/2022
Social Slider Feed <= 2.0.5 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via API key in versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-2.0.5
2.0.6
02/08/2022
Social Slider Feed <= 2.0.4 – Missing Authorization
The Social Slider Feed plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.4. This is due to missing capability checks and nonce validation on the 'showPageContent' function. This makes it possible for…
*-2.0.4
2.0.5
01/08/2022
Social Slider Feed <= 2.0.4 – Authenticated (Scubscriber+) Stored Cross-Site Scripting
The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level…
*-2.0.4
2.0.5
01/08/2022
Social Slider Feed <= 2.0.4 – Missing Authorization to Cross-Site Scripting
The Social Slider Feed plugin for WordPress is vulnerable to authenticated arbitrary API key update via the YouTube API key in versions up to, and including 2.0.4. This makes it possible for a subscriber-level attacker to change the…
*-2.0.4
2.0.5
01/08/2022
Social Slider Feed <= 2.0.4 – Reflected Cross-Site Scripting
The Social Slider Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.0.4. This makes it possible for unauthenticated…
*-2.0.4
2.0.5
01/08/2022
Social Slider Widget <= 1.8.4 – Reflected Cross-Site Scripting
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
[*, 1.8.5)
1.8.5
14/03/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.