ParOne Feeds
ParOne Feeds has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for ParOne Feeds has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. ParOne Feeds is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-51874ParOne Feeds <= 1.17.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
ParOne Feeds
Author
ParOne, Inc
This plugin is a tool for distributing ParOne, Inc video feeds into WordPress installations. This plugin is a tool for distributing golf video supplied by ParOne, Inc into WordPress installations. Users of this plugin have registered with ParOne, Inc to distribute content into their WordPress site. More information about ParOne can be found here. How it works This plugin installs ParOne’s custom video player web components via CDN, and provides shortcodes for including those components in WordPress pages and posts. The video player web components interact with ParOne as an external service. In addition, this plugin allows the WordPress administrator to configure auto-posting of video content into WordPress. The interaction with the ParOne video service consists of 3 types of interactions: Downloading the script which contains the video player web components Calling ParOne’s content API to request lists of eligible videos Calling ParOne’s tracking API to signal when a video starts to be played, and when the playhead hits 5, 15, and 30 seconds ParOne collects no personally identifiable information. Tracking calls are used for registering views on WordPress sites. This plugin includes shortcodes which can be placed on any page. Support Technical documentation can be found here
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C