CVE-2023-49861 – Social Media Feather <= 2.1.3 - Missing Authorization
https://notcve.org/view.php?id=CVE-2023-49861
The Social Media Feather plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on two functions in versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to hide notices. • CWE-862: Missing Authorization •
CVE-2021-36848 – WordPress Social Media Feather plugin <= 2.0.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2021-36848
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versions <= 2.0.4 Una vulnerabilidad de tipo Cross-Site Scripting (XSS) Autenticado (admin+) en Social Media Feather (plugin de WordPress) versiones anteriores a 2.0.4 incluyéndola • https://patchstack.com/database/vulnerability/social-media-feather/wordpress-social-media-feather-plugin-2-0-4-authenticated-stored-cross-site-scripting-xss-vulnerability https://wordpress.org/plugins/social-media-feather/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •