2 results (0.030 seconds)

CVSS: 4.3EPSS: %CPEs: 1EXPL: 0

The Social Media Feather plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on two functions in versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to hide notices. • CWE-862: Missing Authorization •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versions <= 2.0.4 Una vulnerabilidad de tipo Cross-Site Scripting (XSS) Autenticado (admin+) en Social Media Feather (plugin de WordPress) versiones anteriores a 2.0.4 incluyéndola • https://patchstack.com/database/vulnerability/social-media-feather/wordpress-social-media-feather-plugin-2-0-4-authenticated-stored-cross-site-scripting-xss-vulnerability https://wordpress.org/plugins/social-media-feather/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •