CVE-2016-10986: Nerdcow Tweet Wheel

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_token_secret.

Affected products

  • Nerdcow Tweet Wheel: before 1.0.3.3 (fixed in 1.0.3.3)

Published 2019-09-17. Last modified 2026-06-17.