vendor:
Instagram Feed WordPress Plugin
by:
Securify
N/A
CVSS
N/A
Cross-Site Scripting
Cross-Site Scripting (XSS)
CWE
Product Name: Instagram Feed WordPress Plugin
Affected Version From: 1.4.6.2
Affected Version To: 1.4.2007
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: WordPress
2016
Persistent Cross-Site Scripting in Instagram Feed plugin via CSRF
A persistent Cross-Site Scripting vulnerability was found in the Instagram Feed plugin. This issue allows an attacker to perform a wide variety of actions, such as stealing Administrators' session tokens, or performing arbitrary actions on their behalf. In order to exploit this issue, the attacker has to lure/force a logged on WordPress Administrator into opening a URL provided by an attacker.
Mitigation:
This issue is resolved in Instagram Feed WordPress Plugin version 1.4.7. It is recommended to update to the latest version.