// For flags

CVE-2021-25120

Easy Social Feed < 6.2.7 - Reflected Cross-Site Scripting

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

Los plugins Easy Social Feed Free y Pro de WordPress versiones anteriores a 6.2.7, no sanean algunos de los parĂ¡metros usados por medio de acciones AJAX antes de devolverlos a la respuesta, conllevando a problemas de tipo Cross-Site Scripting reflejado

*Credits: Thura Moe Myint
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-14 CVE Reserved
  • 2022-04-11 CVE Published
  • 2023-11-09 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Easysocialfeed
Search vendor "Easysocialfeed"
Easy Social Feed
Search vendor "Easysocialfeed" for product "Easy Social Feed"
< 6.2.7
Search vendor "Easysocialfeed" for product "Easy Social Feed" and version " < 6.2.7"
pro, wordpress
Affected
Easysocialfeed
Search vendor "Easysocialfeed"
Easy Social Feed
Search vendor "Easysocialfeed" for product "Easy Social Feed"
< 6.3.4
Search vendor "Easysocialfeed" for product "Easy Social Feed" and version " < 6.3.4"
free, wordpress
Affected