cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-9607,https://securityvulnerability.io/vulnerability/CVE-2024-9607,Unauthenticated Attackers Can Inject Arbitrary Web Scripts Through Reflected Cross-Site Scripting in 10Web Social Post Feed Plugin,"The 10Web Social Post Feed plugin for WordPress is susceptible to Reflected Cross-Site Scripting due to improper handling of query parameters via the add_query_arg function. This vulnerability affects all versions up to and including 1.2.9. Unauthenticated attackers could exploit this flaw by crafting malicious links that, when clicked by users, execute arbitrary scripts within their web browsers. This exploit can occur specifically when the 'leave a review' notification is displayed on the webpage, creating an opportunity for attackers to manipulate user actions.",Wordpress,10web Social Post Feed,6.1,MEDIUM,0.0004600000102072954,false,,false,false,false,,false,false,2024-10-25T06:51:26.121Z,0 CVE-2023-2503,https://securityvulnerability.io/vulnerability/CVE-2023-2503,10WebSocial < 1.2.9 - Reflected XSS,"The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin",Wordpress,10web Social Post Feed,6.1,MEDIUM,0.0007600000244565308,false,,false,false,false,,false,false,2023-06-05T14:15:00.000Z,0