All 3 CVE vulnerabilities found in Custom Twitter Feeds – A Tweets Widget or X Feed Widget, with AI-generated Chinese analysis, references, and POCs.
Vendor: Smash Balloon
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-1314 | Custom Twitter Feeds <= 2.2.5 - Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin Function CWE-352 | 4.3 | Medium | 2025-03-20 |
| CVE-2024-0379 | Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Update CWE-352 | 4.3 | Medium | 2024-02-20 |
| CVE-2023-52136 | WordPress Custom Twitter Feeds (Tweets Widget) Plugin <= 2.1.2 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 | 4.3 | Medium | 2024-01-05 |
All 3 known CVE vulnerabilities affecting Custom Twitter Feeds – A Tweets Widget or X Feed Widget with full Chinese analysis, references, and POCs where available.