CVE-2021-25047: 10Web Social Photo Feed < 1.4.29 - Reflected Cross-Site Scripting (XSS)
The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdiapplychanges admin page, allowing an attacker to perform such attack against any logged in users
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25047?
CVE-2021-25047 is a Cross-Site Scripting (XSS) vulnerability in the 10Web Social Photo Feed WordPress plugin before version 1.4.29.
What is the severity of CVE-2021-25047?
The severity of CVE-2021-25047 is medium with a CVSS score of 6.1.
How does CVE-2021-25047 affect the 10Web Social Photo Feed WordPress plugin?
CVE-2021-25047 affects the 10Web Social Photo Feed WordPress plugin before version 1.4.29, allowing an attacker to perform a reflected Cross-Site Scripting (XSS) attack against any logged in users.
How can I fix CVE-2021-25047 in the 10Web Social Photo Feed WordPress plugin?
To fix CVE-2021-25047, update the 10Web Social Photo Feed WordPress plugin to version 1.4.29 or later.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2021-25047?
The Common Weakness Enumeration (CWE) ID associated with CVE-2021-25047 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').