What this page helps you verify fast
This hub clusters every indexed record for flickrRSS so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin flickrRSS (`flickr-rss`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2018-6466, CVE-2018-6467 and CVE-2018-6468, so operators can jump from disclosure to patch validation without scanning the full feed first.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
flickrRSS <= 5.3.1 - Cross-Site Scripting via flickrRSS_set
flickrRSS <= 5.3.1 - Cross-Site Scripting via flickrRSS_id
flickrRSS <= 5.3.1 - Cross-Site Scripting via flickrRSS_tags
flickrRSS <= 5.3.1 - Cross-Site Request Forgery
This hub clusters every indexed record for flickrRSS so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_set p...
The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php. This makes it possible for unauthenticated attackers to change plugin settings via forged request granted...
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_id pa...
Sorted by latest disclosure date so newly published issues surface first.
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_set parameter to wp-admin/options-general.php.
The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php. This makes it possible for unauthenticated attackers to change plugin settings via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_id parameter to wp-admin/options-general.php.
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_tags parameter to wp-admin/options-general.php.