cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forblossomthemes-instagram-feed blossomthemes-instagram-feed

Direction: descending
Jul 05, 2025

BlossomThemes Social Feed # 8fdec6763b3c730130b642406e93234959989593

Date
-
Research Description
BlossomThemes Social Feed [blossomthemes-instagram-feed] <= 2.0.5 (unfixed) Multiple Plugins &lt;= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.
Affected versions
Min -, max -.
Status
vulnerable