VYPR

Wp Social Ninja

by WordPress

CVEs (4)

  • CVE-2025-64375MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Mahmudul Hasan Arif WP Social Ninja wp-social-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Social Ninja: from n/a through <= 3.20.1.

  • CVE-2025-13880MedDec 17, 2025
    risk 0.42cvss 6.5epss 0.00

    The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the getAdvanceSettings and…

  • CVE-2025-13007MedDec 2, 2025
    risk 0.40cvss 6.1epss 0.00

    The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping on externally-sourced content.…

  • CVE-2026-65521MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.