Known Vulnerabilities for Featured Posts by Bestwebsoft
Listed below are 1 of the newest known vulnerabilities associated with "Featured Posts" by "Bestwebsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-32245 json | Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll featured-posts-scroll allows Stored XSS.Th... | Not Provided | 2025-05-16 | 2026-04-23 |
| CVE-2025-28905 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chaser324 Featured Post... | Not Provided | 2025-03-11 | 2026-04-23 |
| CVE-2025-13794 json | The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to ... | Not Provided | 2025-12-16 | 2026-04-08 |
| CVE-2025-11828 json | The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in... | Not Provided | 2025-11-11 | 2026-04-08 |
| CVE-2024-48032 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sumitsurai Featured Pos... | Not Provided | 2024-10-17 | 2026-04-23 |
| CVE-2024-48031 json | Cross-Site Request Forgery (CSRF) vulnerability in sumitsurai Featured Posts with Multiple Custom Groups (FPMCG) featured-pos... | Not Provided | 2024-10-17 | 2026-04-23 |
| CVE-2024-3664 json | The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... | Not Provided | 2024-04-23 | 2026-04-08 |
| CVE-2023-2764 json | The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... | Not Provided | 2023-06-09 | 2026-04-08 |
| CVE-2017-2171 json | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi p... | 6.1 - MEDIUM | 2017-05-22 | 2017-06-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bestwebsoft | Featured Posts | 1.0.2 | |||
| Application | Bestwebsoft | Featured Posts | 1.0.0 |