← back
CVE-2021-25120CWE-79

Easy Social Feed < 6.2.7 - Reflected Cross-Site Scripting

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 2.9%
exploitation probability
2.9%top 14% of all CVEs
observed exploitation
nono source reports it
The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues