Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute
medium
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 6.4
- Affected:
- up to 4.9.0
- Fixed in:
- 4.10.0
- Disclosed:
- Aug 15, 2026
CVE-2026-16775 on NVD →
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] <= 4.3.2 (unfixed)
unknown
[en] Missing Authorization vulnerability in Syed Balkhi Smash Balloon Social Post Feed custom-facebook-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smash Balloon Social Post Feed: from n/a through <= 4.3.2.
- Affected:
- up to 4.3.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-49937 on NVD →
Smash Balloon Social Post Feed <= 4.3.2 - Missing Authorization
medium
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to per...
- CVSS:
- 4.3
- Affected:
- up to 4.3.2
- Fixed in:
- 4.3.3
- Disclosed:
- Oct 9, 2025
CVE-2025-49937 on NVD →
Smash Balloon Custom Facebook Feed <= 4.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute
medium
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-color attribute in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 6.4
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.2
- Disclosed:
- Jun 9, 2025
CVE-2025-4577 on NVD →
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.2.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Smash Balloon Social Post Feed.This issue affects Smash Balloon Social Post Feed: from n/a through 4.2.1.
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.2
- Disclosed:
- Apr 15, 2024
CVE-2024-31379 on NVD →
Smash Balloon Social Post Feed <= 4.2.1 - Cross-Site Request Forgery
medium
The Smash Balloon Social Post Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.1. This is due to missing or incorrect nonce validation on the maybe_source_connection_data() function. This makes it possible for unauthenticated attackers to check connection data...
- CVSS:
- 4.3
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Apr 10, 2024
CVE-2024-31379 on NVD →
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.1.6
unknown
[en] The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.6
- Disclosed:
- Jan 16, 2023
CVE-2022-4477 on NVD →
Smash Balloon Social Post Feed <= 4.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Smash Balloon Social Post Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inje...
- CVSS:
- 6.4
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Dec 20, 2022
CVE-2022-4477 on NVD →
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.1.1
unknown
[en] The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Jan 17, 2022
CVE-2021-25065 on NVD →
Smash Balloon Social Post Feed <= 4.1 - Reflected Cross-Site Scripting
medium
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
- CVSS:
- 5.4
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Dec 16, 2021
CVE-2021-25065 on NVD →
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.0.1
unknown
[en] The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.1
- Disclosed:
- Nov 29, 2021
CVE-2021-24918 on NVD →
Smash Balloon Social Post Feed <= 4.0 - Arbitrary Plugin Settings Update to Stored Cross-Site Scripting
medium
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
- CVSS:
- 5.4
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.1
- Disclosed:
- Oct 29, 2021
CVE-2021-24918 on NVD →
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 2.19.2
unknown
[en] The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Store...
- Affected:
- up to 2.19.2
- Fixed in:
- 2.19.2
- Disclosed:
- Sep 13, 2021
CVE-2021-24508 on NVD →
Smash Balloon Social Post Feed <= 2.19.1 - Unauthenticated Stored Cross-Site Scripting
medium
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cro...
- CVSS:
- 6.1
- Affected:
- up to 2.19.2
- Fixed in:
- 2.19.2
- Disclosed:
- Aug 16, 2021
CVE-2021-24508 on NVD →
Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting
medium
Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- CVSS:
- 6.1
- Affected:
- up to 2.19.1
- Fixed in:
- 2.19.2
- Disclosed:
- Jul 20, 2021
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 2.19.2
unknown
Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- Affected:
- up to 2.19.2
- Fixed in:
- 2.19.2
- Disclosed:
- Jul 20, 2021
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.3.2
unknown
- Affected:
- up to 4.3.2
- Fixed in:
- 4.3.2
CVE-2025-4577 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database