The Feed Them Social plugin for WordPress is vulnerable to security issues in versions up to and including 2.9.9. Attackers could inject malicious code in pages by luring users to take certain actions, such as clicking on a link. This could be done by exploiting the lack of input sanitization and output escaping of a parameter called ‘expires_in’.