WordPress security by component
Custom Twitter Feeds – A Tweets Widget or X Feed Widget
Plugin description
Custom Twitter Feeds – A Tweets Widget or X Feed Widget is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published May 13, 2026; the highest published CVSS base score is 7.2.
Plugin slug:
custom-twitter-feedsLatest vulnerability
CVE-2026-6177: Custom Twitter Feeds – A Tweets Widget or X Feed Widget: Cross-site scripting
Custom Twitter Feeds – A Tweets Widget or X Feed Widget is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.5.4. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| May 13, 2026 |
CVE-2026-6177
Custom Twitter Feeds – A Tweets Widget or X Feed Widget: Cross-site scripting
Custom Twitter Feeds – A Tweets Widget or X Feed Widget is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.5.4. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Mar 20, 2025 |
CVE-2025-1314
Custom Twitter Feeds – A Tweets Widget or X Feed Widget: Cross-site request forgery
Custom Twitter Feeds – A Tweets Widget or X Feed Widget is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 31, 2024 |
CVE-2024-49685
Custom Twitter Feeds (Tweets Widget): Cross-site request forgery
Custom Twitter Feeds (Tweets Widget) is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Oct 08, 2024 |
CVE-2024-8983
Custom Twitter Feeds: Cross-site scripting
Custom Twitter Feeds is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Feb 29, 2024 |
CVE-2024-0379
Custom Twitter Feeds – A Tweets Widget or X Feed Widget: Cross-site request forgery
Custom Twitter Feeds – A Tweets Widget or X Feed Widget is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 05, 2024 |
CVE-2023-52136
Custom Twitter Feeds – A Tweets Widget or X Feed Widget: Cross-site request forgery
Custom Twitter Feeds – A Tweets Widget or X Feed Widget is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| May 29, 2023 |
CVE-2022-33974
Custom Twitter Feeds: Cross-site request forgery
Custom Twitter Feeds is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVD8.8
|