nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25065 CVE-2021-25065
MEDIUMNuclei
Smash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2021-25065 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Smash Balloon Social Post Feed | CVE List | 4.1.1 to < 4.1.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMSmash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site ScriptingCVSS 5.4
The plugin was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
Impact
An attacker can exploit this vulnerability to inject malicious scripts into web pages viewed by authenticated users, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Fixed in version 2.19.2
WeaknessesCWE-79
AuthorsHarsh
Template tagscve2021cvewpscanwordpresswp-pluginxsswpauthenticatedsmashballoonvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:smashballoon:smash_balloon_social_post_feed:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/custom-facebook-feed/
FOFA: body=/wp-content/plugins/custom-facebook-feed/
https://wpscan.com/vulnerability/ae1aab4e-b00a-458b-a176-85761655bdcc https://wordpress.org/plugins/custom-facebook-feed/
Source: ProjectDiscovery
References
2wpscan.com
https://wpscan.com/vulnerability/ae1aab4e-b00a-458b-a176-85761655bdcc