CVE-2024-8983: Custom Twitter Feeds < 2.2.3 - Admin+ Stored XSS
Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8983?
CVE-2024-8983 has a high severity rating due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-8983?
To fix CVE-2024-8983, update the Custom Twitter Feeds WordPress plugin to version 2.2.3 or later.
What type of attack does CVE-2024-8983 allow?
CVE-2024-8983 allows high privilege users to inject scripts through unfiltered settings in the plugin.
Who is affected by CVE-2024-8983?
Users of the Custom Twitter Feeds WordPress plugin prior to version 2.2.3 are affected by CVE-2024-8983.
What are the implications of CVE-2024-8983 exploitation?
Exploitation of CVE-2024-8983 can lead to unauthorized script execution, compromising site integrity and user data.