Description
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable on common installs where the admin has configured access tokens with zero or multiple legacy feeds, as this causes the ctf_statuses support_legacy_shortcode option to be set to boolean true by default, activating the unfiltered legacy shortcode attribute code path.
Published: 2026-09-18
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) via shortcode attribute
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the Custom Twitter Feeds WordPress plugin and allows authenticated users with contributor‑level privileges or higher to insert arbitrary JavaScript into the page via the "buttoncolor" shortcode attribute. The input is not sufficiently sanitized or escaped before being stored, which means the script is saved in the database and executed in any browser that renders the affected page. This can lead to theft of session information, defacement, or execution of further malicious code by unsuspecting site visitors.

Affected Systems

All installations of the Custom Twitter Feeds plugin version 2.8.0 and earlier are vulnerable. The issue manifests when contributors or administrators can edit posts or widgets that use the plugin’s shortcode, especially when the legacy shortcode support option is enabled due to legacy feed configuration or legacy token usage. Typical WordPress sites that have this plugin and provide contributor access to the frontend are at risk.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of observed exploitation at this time; the vulnerability is not currently listed in the CISA KEV catalog. An attacker still could exploit the flaw by authenticated access to the WordPress backend, inserting a malicious shortcode in a page or post, which is then stored and served to all users. The impact is primarily a stored XSS that affects the confidentiality and integrity of user sessions and the availability of the site’s content to those users.

Generated by OpenCVE AI on September 19, 2026 at 20:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Custom Twitter Feeds plugin to the latest version, which removes the unfiltered legacy shortcode path.
  • If an upgrade is not immediately possible, disable the legacy shortcode support by setting the plugin option "support_legacy_shortcode" to false through the plugin’s settings or by editing the corresponding database entry.
  • Restrict the contributor role so that it cannot create or edit content that includes the plugin’s shortcode, limiting privileged access to administrators only.
  • Review and sanitize existing posts or pages that contain the "buttoncolor" attribute, removing any malicious scripting or replacing the attribute with safe values.

Generated by OpenCVE AI on September 19, 2026 at 20:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Smub
Smub custom Twitter Feeds – A Tweets Widget Or X Feed Widget
Wordpress
Wordpress wordpress
Vendors & Products Smub
Smub custom Twitter Feeds – A Tweets Widget Or X Feed Widget
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable on common installs where the admin has configured access tokens with zero or multiple legacy feeds, as this causes the ctf_statuses support_legacy_shortcode option to be set to boolean true by default, activating the unfiltered legacy shortcode attribute code path.
Title Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Smub Custom Twitter Feeds – A Tweets Widget Or X Feed Widget
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:31:44.098Z

Reserved: 2026-09-02T15:42:41.203Z

Link: CVE-2026-84909

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:55.816Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:50.390

Modified: 2026-09-18T15:17:14.100

Link: CVE-2026-84909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')