Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snapwidget SnapWidget Social Photo Feed Widget snapwidget-wp-instagram-widget allows DOM-Based XSS.This issue affects SnapWidget Social Photo Feed Widget: from n/a through <= 1.1.0.
Published: 2025-09-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during web page generation allows a DOM‑based XSS flaw in the SnapWidget Social Photo Feed Widget. The vulnerability can enable an attacker to inject and execute arbitrary JavaScript in the browser context of any user who views the widget. This could lead to theft of session cookies, defacement of the site, or further phishing attempts delivered to legitimate visitors. The weakness is reflected in CWE‑79, indicating non‑recommendation of proper input validation and output encoding.

Affected Systems

The SnapWidget Social Photo Feed Widget plugin versions up to and including 1.1.0 are affected. No further patch level information is provided, so all releases through 1.1.0 remain vulnerable.

Risk and Exploitability

The CVSS score of 6.5 signals a moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector appears to be DOM‑based XSS triggered through the plugin’s front‑end. An attacker would need to embed malicious payloads in the widget data or configuration, which can be executed automatically when the page loads in the victim’s browser. While the attack does not provide remote code execution on the server, it can subvert the user session and compromise confidentiality and integrity on the client side.

Generated by OpenCVE AI on April 30, 2026 at 01:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SnapWidget Social Photo Feed Widget to the latest available version to eliminate the vulnerability.
  • Delete or disable any unused instances of the widget so that affected code is not served to visitors.
  • If an upgrade cannot be deployed immediately, remove the widget from active themes or pages to stop the vulnerable code from loading.

Generated by OpenCVE AI on April 30, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30564 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snapwidget SnapWidget Social Photo Feed Widget allows DOM-Based XSS. This issue affects SnapWidget Social Photo Feed Widget: from n/a through 1.1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snapwidget SnapWidget Social Photo Feed Widget allows DOM-Based XSS. This issue affects SnapWidget Social Photo Feed Widget: from n/a through 1.1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snapwidget SnapWidget Social Photo Feed Widget snapwidget-wp-instagram-widget allows DOM-Based XSS.This issue affects SnapWidget Social Photo Feed Widget: from n/a through <= 1.1.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 23 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snapwidget SnapWidget Social Photo Feed Widget allows DOM-Based XSS. This issue affects SnapWidget Social Photo Feed Widget: from n/a through 1.1.0.
Title WordPress SnapWidget Social Photo Feed Widget Plugin <= 1.1.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:56:39.406Z

Reserved: 2025-08-27T16:19:35.850Z

Link: CVE-2025-58241

cve-icon Vulnrichment

Updated: 2025-09-23T15:57:33.934Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:09.713

Modified: 2026-04-23T15:33:22.030

Link: CVE-2025-58241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T01:30:24Z

Weaknesses