Skip to main content

Vendor/product archive

nextscripts / social_networks_auto_poster CVEs

Beta · best-effort

10 CVEs tagged to nextscripts / social_networks_auto_poster0 Critical, 3 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2024-37275

Published Jul 22, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2088

Published May 22, 2024

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSe…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1762

Published May 22, 2024

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_USER_AGENT header in all versions up to, and including,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1446

Published May 22, 2024

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing o…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49183

Published Dec 15, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.Thi…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-25072

Published Feb 1, 2022

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin dele…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24975

Published Feb 1, 2022

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, lea…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38356

Published Nov 1, 2021

The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1