🔐 CVE Alert

CVE-2026-84909

MEDIUM 6.4

Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable on common installs where the admin has configured access tokens with zero or multiple legacy feeds, as this causes the ctf_statuses support_legacy_shortcode option to be set to boolean true by default, activating the unfiltered legacy shortcode attribute code path.

CWE CWE-79
Vendor smub
Product custom twitter feeds – a tweets widget or x feed widget
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for smub custom twitter feeds – a tweets widget or x feed widget

Be the first to know when new medium vulnerabilities affecting smub custom twitter feeds – a tweets widget or x feed widget are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

smub / Custom Twitter Feeds – A Tweets Widget or X Feed Widget
0 ≤ 2.8.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/b1a9d042-c0c0-477a-8cdf-9fb9d2239059?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/custom-twitter-feeds/tags/2.8.0/inc/CtfFeed.php#L2338 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/custom-twitter-feeds/tags/2.8.0/inc/CTF_Parse.php#L551 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/custom-twitter-feeds/tags/2.8.0/inc/CtfFeed.php#L2001 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/custom-twitter-feeds/tags/2.8.0/inc/CTF_Settings.php#L293 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/custom-twitter-feeds/tags/2.8.0/inc/CTF_Settings.php#L234 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/custom-twitter-feeds/tags/2.8.0/inc/CtfFeed.php#L139 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/custom-twitter-feeds/tags/2.8.0/custom-twitter-feed.php#L432 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?reponame=&new=3695675%40custom-twitter-feeds&old=3665650%40custom-twitter-feeds

Credits

Wordfence PRISM