Showing 1 vulnerability on this page for smash_balloon_social_post_feed

Signals CISA KEV Ransomware Nuclei
smashballoon vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to Stored XSS

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

CWE-79Nov 29, 2021
CVSS5.4v3.1EPSS0.654%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX