CVE Database /
CVE-2021-24508
CVE · Medium
CVE-2021-24508 — Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 2.19.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24508
|
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 2.19.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.19.2
|
2.19.2 |
2021-08-16 |
—
|
CVE-2021-24508
The Smash Balloon Social Post Feed plugin before version 2.19.2 contains a stored cross-site scripting vulnerability in its feed_locator AJAX action, which is accessible to both authenticated and unauthenticated users. The feedID POST parameter fails to undergo proper sanitization or escaping, allowing attackers to inject malicious scripts that are later displayed in the admin dashboard. When an administrator views this content, the injected code executes with their privileges, even though the initial attack requires no authentication.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings