CVE-2016-10986: Nerdcow Tweet Wheel
Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.
The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_token_secret.
Affected products
- Nerdcow Tweet Wheel: before 1.0.3.3 (fixed in 1.0.3.3)
Published 2019-09-17. Last modified 2026-06-17.