cleantalk
Vulnerabilities and Security Researches

Easy Social Feed – Social Photos Gallery – Post Feed – Like Box, CVE-2021-25120

CVE, Research URL

CVE-2021-25120

Published on
Apr 18, 2022
Research Description
The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues
Affected versions
Min -, max 6.2.7.
Status
vulnerable