Medium severity6.1NVD Advisory· Published Apr 23, 2018· Updated Jun 17, 2026
CVE-2018-10301
CVE-2018-10301
Description
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram post.
Affected products
3<1.3.1+ 1 more
- (no CPE)range: <1.3.1
- (no CPE)range: <1.3.1
- cpe:2.3:a:web-dorado:wd_instagram_feed:*:*:*:*:premium:wordpress:*:*Range: <1.3.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.