cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcustom-twitter-feeds custom-twitter-feeds

Direction: ascending
Jun 07, 2024

Custom Twitter Feeds – A Tweets Widget or X Feed Widget # CVE-2022-33974

CVE, Research URL

CVE-2022-33974

Date
May 29, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.
Affected versions
Min -, max -.
Status
vulnerable

Custom Twitter Feeds &#8211; A Tweets Widget or X Feed Widget # CVE-2023-52136

CVE, Research URL

CVE-2023-52136

Date
Jan 05, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget or X Feed Widget: from n/a through 2.1.2.
Affected versions
Min -, max -.
Status
vulnerable

Custom Twitter Feeds &#8211; A Tweets Widget or X Feed Widget # CVE-2024-0379

CVE, Research URL

CVE-2024-0379

Date
Feb 29, 2024
Research Description
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers to update the site's twitter API token and secret via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Oct 09, 2024

Custom Twitter Feeds &#8211; A Tweets Widget or X Feed Widget # CVE-2024-8983

CVE, Research URL

CVE-2024-8983

Date
Oct 08, 2024
Research Description
Custom Twitter Feeds WordPress plugin before 2.2.3 is not filtering some of its settings allowing high privilege users to inject scripts.
Affected versions
Min -, max -.
Status
vulnerable
Oct 25, 2024

Custom Twitter Feeds &#8211; A Tweets Widget or X Feed Widget # CVE-2024-49685

CVE, Research URL

CVE-2024-49685

Date
Oct 31, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets Widget): from n/a through 2.2.3.
Affected versions
Min -, max -.
Status
vulnerable
Mar 21, 2025

Custom Twitter Feeds &#8211; A Tweets Widget or X Feed Widget # CVE-2025-1314

CVE, Research URL

CVE-2025-1314

Date
Mar 20, 2025
Research Description
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or incorrect nonce validation on the ctf_clear_cache_admin() function. This makes it possible for unauthenticated attackers to reset the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable