Cross-Site Scripting Vulnerability in Twitter Feed 0.3.1 for WordPress
WordPress® is a popular open-source blogging tool that millions of websites throughout the world use. The Twitter® Feed plugin lets users pull Twitter data into their page.
Affected Application: Twitter Feed plugin wp-twitter-feed 0.3.1.
Issue: On 08/24/11, a cross-site scripting vulnerability was reported for the WordPress Twitter Feed plugin, wp-twitter-feed. Attackers can use the vulnerability in the magpie_debug.php script to steal authentication information from cookies and perform other malicious attacks.
Resolution: An update for Twitter Feed is available. For more information, visit the vendor's website: http://pleer.co.uk/wordpress/plugins/wp-twitter-feed/.
This information was compiled using information in the National Vulnerability Database. For more information about this issue, see the summary for CVE-2010-4825. To learn more about cross-site scripting vulnerabilities, see Cross-Site Scripting.
Website Protection Site Scanner scans for this vulnerability, and many more. To learn about Site Scanner, see Getting Started with Website Protection Site Scanner.