What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Sternberg DsgnWrks Twitter Importer dsgnwrks-twitter-importer allows Reflected XSS.This issue affects DsgnWrks Twitter Importer: from n/a through <= 1.1.4.
Explanation of Vulnerability in Simple Terms
02Summary
DsgnWrks Twitter Importer versions 1.1.4 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a victim's browser when they visit an affected page. The vulnerability requires user interaction and can affect other users or site functionality. Update to a version newer than 1.1.4 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in a victim's browser, potentially stealing session data or performing actions on their behalf.
Potential impact on your site
04Site Impact
Site visitors may have their sessions compromised or be redirected to malicious sites; site reputation and user trust at risk.
Conditions required to exploit
05Prerequisites
Victim must visit a page containing the attacker's malicious input; no authentication required.
Key dates
06Disclosure timeline
March 3, 2025
CVE published
May 11, 2026
Record updated