CVE-2019-14470: Instagram-PHP-API Project Instagram-PHP-API
Medium severity, CVSS 6.1. EPSS: 83% chance of exploitation in the next 30 days.
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.
Affected products
- Instagram-PHP-API Project Instagram-PHP-API: affected versions not specified
- Userproplugin User Pro: up to and including 4.9.32
Published 2019-09-04. Last modified 2026-06-17.