Record summary

CVE-2021-25055 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

FeedWordPress

CVE List2022.0123 to < 2022.0123affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress FeedWordPress < 2022.0123 - Authenticated Cross-Site ScriptingCVSS 6.1

The plugin is affected by a cross-site scripting vulnerability within the "visibility" parameter.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access, data theft, and potential compromise of the affected WordPress website.

Remediation

Update to the latest version of the FeedWordPress plugin (version 2022.0123 or higher) to mitigate the vulnerability.

WeaknessesCWE-79
AuthorsDhiyaneshDK
Template tagscve2021cvewordpressxsswp-pluginauthenticatedwpscanfeedwordpress_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:feedwordpress_project:feedwordpress:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3