Record summary

CVE-2021-25120 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Easy Social Feed Pro

CVE List6.2.7 to < 6.2.7affected

Easy Social Feed – Social Photos Gallery – Post Feed – Like Box

CVE List6.2.7 to < 6.2.7affected

Nuclei templates

1
ProjectDiscoveryMEDIUMEasy Social Feed < 6.2.7 - Cross-Site ScriptingCVSS 6.1

Easy Social Feed < 6.2.7 is susceptible to reflected cross-site scripting because the plugin does not sanitize and escape a parameter before outputting it back in an admin dashboard page, leading to it being executed in the context of a logged admin or editor.

Impact

Attackers can inject malicious JavaScript via reflected XSS in the type parameter, potentially stealing administrator session cookies or modifying social feed configurations.

Remediation

Update to Easy Social Feed version 6.2.7 or later to mitigate the vulnerability.

WeaknessesCWE-79
AuthorsdhiyaneshDk
Template tagscve2021cvewordpresswp-pluginxssauthenticatedwpscaneasysocialfeedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:easysocialfeed:easy_social_feed:*:*:*:*:pro:wordpress:*:*

Source: ProjectDiscovery

References

2