jetpack.com
https://jetpack.com/2021/10/29/security-issues-patched-in-smash-balloon-social-post-feed-plugin CVE-2021-24918
MEDIUM
Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to Stored XSS
Record summary
CVE-2021-24918 has a selected CVSS score of 5.4 (medium).
Description
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 23, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Smash Balloon Social Post Feed | CVE List | 4.0.1 to < 4.0.1 | affected |
smash_balloon_social_post_feedBrowse smashballoon / smash_balloon_social_post_feed | VulnCheck | Version data not supplied | |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24918 wpscan.com
https://wpscan.com/vulnerability/5d252ad7-bf28-44f3-8cd0-c4fe05c48f35