Input validation vulnerability in Custom Twitter Feeds – A Tweets Widget or X Feed Widget 2.1.2

The Custom Twitter Feeds (Tweets Widget) plugin for WordPress is vulnerable to Cross-Site Request Forgery in certain versions. This is an issue because it could allow unauthenticated attackers to make a forged request that would trick a site administrator into performing an action that they did not intend to do. This can be prevented by updating the plugin to the latest version, which includes the necessary nonce validation.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.