PT-2026-95271 · WordPress · Custom Twitter Feeds
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Custom Twitter Feeds – A Tweets Widget or X Feed Widget versions prior to 2.8.1
Description
Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting. This is achieved by injecting arbitrary web scripts through the
buttoncolor shortcode attribute. The issue occurs when the ctf statuses support legacy shortcode option is set to true, which happens by default if the administrator configures access tokens with zero or multiple legacy feeds, thereby activating an unfiltered legacy shortcode attribute code path.Recommendations
Update Custom Twitter Feeds – A Tweets Widget or X Feed Widget to version 2.8.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Custom Twitter Feeds