Medium severity6.1NVD Advisory· Published Apr 18, 2022· Updated Jun 17, 2026
CVE-2021-25120
CVE-2021-25120
Description
The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- WordPress/Easy Social Feed plugindescription
- Range: <6.2.7
cpe:2.3:a:easysocialfeed:easy_social_feed:*:*:*:*:pro:wordpress:*:*+ 1 more
- cpe:2.3:a:easysocialfeed:easy_social_feed:*:*:*:*:pro:wordpress:*:*range: <6.2.7
- cpe:2.3:a:easysocialfeed:easy_social_feed:*:*:*:*:free:wordpress:*:*range: <6.3.4
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/0ad020b5-0d16-4521-8ea7-39cd206ab9f6nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.