4.8
CVSSv3

CVE-2024-13207

CVSSv4: NA | CVSSv3: 4.8 | CVSSv2: NA | VMScore: 580 | EPSS: 0.00027 | KEV: Not Included
Published: 15/04/2025 Updated: 15/04/2025

Vulnerability Summary

Stored XSS Vulnerability in Widget for Social Page Feeds WordPress Plugin

The Widget for Social Page Feeds WordPress plugin before version 6.4.2 has a Cross Site Scripting (XSS) vulnerability. This security issue occurs because the plugin does not properly sanitize and escape certain settings. As a result, high-privilege users like administrators can potentially conduct Stored XSS attacks, even in scenarios where the unfiltered_html capability is restricted, such as in a multisite WordPress environment.