CVE-2021-25120: vulnerability in Easy Social Feed Pro
Easy Social Feed < 6.2.7 - Reflected Cross-Site Scripting
Published · Updated
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 2.9%
exploitation probability
2.9%top 13% of all CVEs
observed exploitation
nono source reports it
The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues