CVE-2022-2383
Feed Them Social < 3.0.1 - Reflected Cross-Site Scripting
Record summary
CVE-2022-2383 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 26, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Feed Them Social – for Twitter feed, Youtube and more | CVE List | 3.0.1 to < 3.0.1 | affected |
feed_them_socialBrowse slickremix / feed_them_social | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Feed Them Social <3.0.1 - Cross-Site ScriptingCVSS 6.1
WordPress Feed Them Social plugin before 3.0.1 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape a parameter before outputting it back in the page.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
Update to the latest version of the Feed Them Social plugin (3.0.1 or higher) to mitigate the XSS vulnerability.
Source: ProjectDiscovery