4.8

CVE-2024-8983

Exploit

Custom Twitter Feeds < 2.2.3 - Admin+ Stored XSS

Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting

Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Mögliche Gegenmaßnahme
Custom Twitter Feeds – A Tweets Widget or X Feed Widget: Update to version 2.2.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SmashballoonCustom Twitter Feeds SwPlatformwordpress Version < 2.2.3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Custom Twitter Feeds – A Tweets Widget or X Feed Widget
Version *-2.2.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.313
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://wpscan.com/vulnerability/29194dde-8d11-4096-a5ae-1d69c2c5dc33/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/ade346fc-d158-4485-85a8-d14d5e059554
Third Party Advisory