smashballoon Vulnerabilities and Affected Products
Vulnerabilities associated with smash_balloon_social_post_feed.
Products
Clear product- custom_twitter_feeds1 vulnerability
- smash_balloon_social_post_feed1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-24918MEDIUM | Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to Stored XSSThe Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages. CWE-79Nov 29, 2021 | CVSS5.4v3.1 | EPSS0.654% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |