Record summary

CVE-2021-25065 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Smash Balloon Social Post Feed

CVE List4.1.1 to < 4.1.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSmash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site ScriptingCVSS 5.4

The plugin was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.

Impact

An attacker can exploit this vulnerability to inject malicious scripts into web pages viewed by authenticated users, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Fixed in version 2.19.2

WeaknessesCWE-79
AuthorsHarsh
Template tagscve2021cvewpscanwordpresswp-pluginxsswpauthenticatedsmashballoonvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:smashballoon:smash_balloon_social_post_feed:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/custom-facebook-feed/
FOFA: body=/wp-content/plugins/custom-facebook-feed/

Source: ProjectDiscovery

References

2