{"error":0,"message":null,"data":{"name":"Recent Posts Widget Extended","plugin":"recent-posts-widget-extended","link":"https:\/\/wordpress.org\/plugins\/recent-posts-widget-extended\/","latest":"1690782180","closed":1,"closed_reason":"security-issue","closed_date":"2025-09-04","vulnerability":[{"uuid":"18b08c737208abe19122f6a748a57f986e634f7777f7a6fce6e5a5eae5fcb143","name":"Recent Posts Widget Extended [recent-posts-widget-extended] < 0.9.9.4 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.9.4","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"3cc7d2ef95e97e36a6ad4e848429845437e5a6e2","name":"WordPress Recent Posts Widget Extended Plugin <= 0.9.9.3 - Authenticated XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/recent-posts-widget-extended\/vulnerability\/wordpress-recent-posts-widget-extended-plugin-0-9-9-3-authenticated-xss","description":"Because of this vulnerability, the attackers can inject arbitrary web script or HTML.\nUpgrade the plugin.","date":"2015-10-19"}],"impact":[]},{"uuid":"b4316acaba4521ef48f4a3c472e696411e0c58c1d2e78dc01f04a9c7fdbc497c","name":"Recent Posts Widget Extended [recent-posts-widget-extended] < 0.9.9.4 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.9.4","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"34ef525742fa9a8bbecda6e973ba149ed22bc619","name":"Recent Posts Widget Extended <= 0.9.9.3 - Cross Site-Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/recent-posts-widget-extended\/recent-posts-widget-extended-0993-cross-site-scripting","description":"The Recent Posts Widget Extended plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.9.9.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2015-10-19"}],"impact":[]},{"uuid":"dcc08b0c62877ec02a2a11014ad6b15050e94eda7ed09c9e25c2214249bd4490","name":"Recent Posts Widget Extended [recent-posts-widget-extended] < 0.9.9.4 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"0.9.9.4","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"2e8c7578-007a-472c-9c80-54e23d42e346","name":"Recent Posts Widget Extended &lt;= 0.9.9.3 - Authenticated XSS (multisite)","link":"https:\/\/wpscan.com\/vulnerability\/2e8c7578-007a-472c-9c80-54e23d42e346","description":"XSS in the Recent Posts Widget Extended plugin allows single site admins to change network admin&#039;s password with simple CSRF described above POC field.\r\n\r\nThis vulnerability is currently unpatched.","date":null}],"impact":[]},{"uuid":"940dcb8242c5e6645a369fd1d4bb435ce05c6ba97e34049a119679a75dcd7635","name":"Recent Posts Widget Extended [recent-posts-widget-extended] <= 2.0.2 (unfixed + closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.2","max_operator":"le","unfixed":"1","closed":"1"},"source":[{"id":"CVE-2025-6757","name":"Recent Posts Widget Extended <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via rpwe Shortcode","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-6757","description":"The Recent Posts Widget Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rpwe' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"03e62d0bc3728d244a8dcdd1cb0262935f19b157","name":"WordPress Recent Posts Widget Extended Plugin <= 2.0.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/recent-posts-widget-extended\/vulnerability\/wordpress-recent-posts-widget-extended-plugin-2-0-2-authenticated-contributor-stored-cross-site-scripting-via-rpwe-shortcode-vulnerability","description":"<p>WordPress Recent Posts Widget Extended Plugin <= 2.0.2 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Recent Posts Widget Extended<\/p><p>Affected Version <= 2.0.2<\/p><p>CVE: CVE-2025-6757<\/p>","date":"2025-09-06"},{"id":"a4c1526593c924036414e297ce2c345089f45796","name":"Recent Posts Widget Extended <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via rpwe Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/recent-posts-widget-extended\/recent-posts-widget-extended-202-authenticated-contributor-stored-cross-site-scripting-via-rpwe-shortcode","description":"The Recent Posts Widget Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rpwe' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-09-05"},{"id":"EUVD-2025-27144","name":"EUVD-2025-27144","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-27144","description":"The Recent Posts Widget Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rpwe' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-09-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1763773340"}