Back to overview

CVE-2026-53736

MEDIUM
4.3
CVSS 3.1
Description
Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates any post regardless of post type.

Metadata

CVE ID
CVE-2026-53736
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-10 17:16 UTC
Published
2026-06-10 20:39 UTC
Last updated
2026-06-11 16:15 UTC
Primary CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Vendor / Product
bplugins / Easy Twitter Feeds
Sources
cve.org  ·  NVD

Severity & Metrics

4.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
bplugins Easy Twitter Feeds 0 < 1.2.13
Weakness (CWE)
CWESourceDescription
CWE-352 cna Cross-Site Request Forgery (CSRF)
CVSS scores (2)
ScoreSeverityVersionSourceVector
5.1 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
4.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
References (2)
Back to overview