Slickremix develops a small portfolio of WordPress plugins, including Feed Them Social and Design Approval System, that extend website functionality and social-media integration for a niche but concentrated user base. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, driven by recurring weaknesses in input validation, cross-site scripting, cross-site request forgery, and deserialization that are endemic to web-plugin architectures handling user-supplied and third-party data. Defenders should monitor this vendor's updates closely and apply patches promptly to exposed WordPress installations; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slickremix over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2383MEDIUM The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | Aug 22, 2022 | 6.1 | 32 | NO | YES |
CVE-2022-2437CRITICAL The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, an | Jul 18, 2022 | 9.8 | 30 | NO | NO |
CVE-2015-9351CRITICAL The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button. | Aug 27, 2019 | 9.8 | 30 | NO | NO |
CVE-2023-25056HIGH Cross-Site Request Forgery (CSRF) vulnerability in SlickRemix Feed Them Social plugin <= 3.0.2 versions. | May 23, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-2532MEDIUM The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | Aug 22, 2022 | 6.1 | 22 | NO | NO |
CVE-2015-9350MEDIUM The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button. | Aug 27, 2019 | 6.1 | 17 | NO | NO |
CVE-2020-36739MEDIUM The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.6. This is due | Jul 1, 2023 | 4.3 | 16 | NO | NO |
CVE-2024-24710MEDIUM Missing Authorization vulnerability in SlickRemix Feed Them Social.This issue affects Feed Them Social: from n/a through 4.2.0. | May 3, 2024 | 4.3 | 15 | NO | NO |
CVE-2013-5711MEDIUM Cross-site scripting (XSS) vulnerability in admin/walkthrough/walkthrough.php in the Design Approval System plugin before 3.7 for WordPress allows remote attackers to inject arbitr | Sep 17, 2013 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slickremix.
Media articles that mention a CVE ID that affects a product developed by Slickremix — matched by CVE ID, not by vendor name.