← Back

Rss Feed Widget

rss_feed_widget

Vendor: Rss Feed Widget Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rss Feed Widget Project
1Rss Feed Widget
Jun 17, 2026
Nov 12, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the co...Show more
The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.Show less
1Rss Feed Widget Project
1Rss Feed Widget
Jun 17, 2026
Aug 26, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can...Show more
Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.Show less