Easysocialfeed maintains a narrowly scoped social-media feed plugin product that, despite limited disclosures, occupies a niche within web-application ecosystems and has acquired public exploit tooling. The recurring vulnerability classes center on web-application input handling and access control, including cross-site scripting, cross-site request forgery, missing authorization, and improper permission assignment, which are characteristic of plugin-based content-aggregation systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easysocialfeed over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25120MEDIUM The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading | Apr 18, 2022 | 6.1 | 31 | NO | YES |
CVE-2024-1219MEDIUM The Easy Social Feed WordPress plugin before 6.5.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users w | Apr 17, 2024 | 5.3 | 20 | NO | NO |
CVE-2024-30180MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Social Feed allows Stored XSS.This issue affects Easy Social Feed: from n | Mar 27, 2024 | 6.5 | 20 | NO | NO |
CVE-2022-4474MEDIUM The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users wi | Jan 23, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-1278MEDIUM The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'efb_likebox' shortcode in al | Mar 21, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-1214MEDIUM The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.4. Th | Mar 21, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-1213MEDIUM The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.4. Th | Mar 21, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-30526MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Easy Social Feed.This issue affects Easy Social Feed: from n/a through 6.5.6. | Mar 31, 2024 | 4.3 | 15 | NO | NO |
CVE-2023-6883MEDIUM The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and | Jan 11, 2024 | 4.3 | 15 | NO | NO |
CVE-2023-48740MEDIUM Missing Authorization vulnerability in Sajid Javed Easy Social Feed easy-facebook-likebox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects | Dec 9, 2024 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easysocialfeed.
Media articles that mention a CVE ID that affects a product developed by Easysocialfeed — matched by CVE ID, not by vendor name.