S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25120 Scanner

CVE-2021-25120 scanner - Cross-Site Scripting (XSS) vulnerability in Easy Social Feed Free and Pro plugins for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25120
6.1
CVSS

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Easy Social Feed Pro
AFFECTED< 6.2.7SAFE ✓≥ 6.2.7
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box
AFFECTED< 6.2.7SAFE ✓≥ 6.2.7
Updated Aug 21, 2026View on NVD →
Detail

The Easy Social Feed Free and Pro WordPress plugins are widely used to integrate social media feeds with WordPress websites. They enable website owners to display feeds from various social media platforms like Facebook, Twitter, Instagram, and Pinterest on their sites. The free version provides basic functionality, while the pro version includes advanced features like custom styling, caching, and filtering options.

Recently, a security flaw was detected in the Easy Social Feed Free and Pro WordPress plugins. The CVE-2021-25120 vulnerability allows attackers to inject malicious code into a website by exploiting non-sanitized parameters used via AJAX actions. This means that attackers can inject scripts that steal sensitive information like user credentials, compromise website functionality and even take over the targeted website altogether.

This vulnerability can lead to serious consequences, including loss of confidential information, compromised website integrity, and reputational damage. It can also impact the ability of a website to generate revenue, and ultimately impact the bottom line of the business.

In conclusion, protecting websites from vulnerabilities like CVE-2021-25120 is critical for all website owners. s4e.io provides an effective platform to learn about vulnerabilities that could impact digital assets quickly. With its pro features, users can easily keep up with the latest security threats and take necessary precautions to secure their digital assets. Stay vigilant and keep your websites secure!

 

REFERENCES

Solution Advice

Website owners can take the following precautions to protect against this vulnerability:

  • Ensure that the Easy Social Feed Free and Pro WordPress plugins are up to date. The latest version – Easy Social Feed Free and Pro 6.2.7 – includes patches for this vulnerability.
  • Use a web application firewall to block malicious traffic and prevent attackers from exploiting the vulnerability.
  • Always implement strong authentication mechanisms like two-factor authentication to protect user accounts from being compromised.
  • Regularly scan the website for vulnerabilities and implement security measures to mitigate them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.