Record summary

CVE-2021-24918 has a selected CVSS score of 5.4 (medium).

Description

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 23, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

2
ProductSourceVersion rangeStatus

Smash Balloon Social Post Feed

CVE List4.0.1 to < 4.0.1affected
VulnCheckVersion data not supplied

References

3