Record summary

CVE-2022-2383 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 26, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Feed Them Social – for Twitter feed, Youtube and more

CVE List3.0.1 to < 3.0.1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Feed Them Social <3.0.1 - Cross-Site ScriptingCVSS 6.1

WordPress Feed Them Social plugin before 3.0.1 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape a parameter before outputting it back in the page.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.

Remediation

Update to the latest version of the Feed Them Social plugin (3.0.1 or higher) to mitigate the XSS vulnerability.

WeaknessesCWE-79
Authorsakincibor
Template tagscvecve2022wpwordpresswp-pluginwpscanxssslickremixvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:slickremix:feed_them_social:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2