Vulnerabilities
Vulnerable Software
The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_TF_password parameter found in the ~/twitter-friends-widget.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.1.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-09-09


Contact Us

Shodan ® - All rights reserved