Social Slider Widget
by Cm Wp
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24196 | Med | 0.35 | 5.4 | 0.01 | Apr 5, 2021 | The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized | ||
| CVE-2024-10149 | Med | 0.31 | 4.8 | 0.00 | May 15, 2025 | The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | ||
| CVE-2025-0717 | Low | 0.23 | 3.5 | 0.00 | Mar 25, 2025 | To exploit the vulnerability, it is necessary: |
- risk 0.35cvss 5.4epss 0.01
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
- risk 0.31cvss 4.8epss 0.00
The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…
- risk 0.23cvss 3.5epss 0.00
To exploit the vulnerability, it is necessary: