CVE · Medium

CVE-2021-24508 — Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 2.19.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24508 Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 2.19.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.19.2 2.19.2 2021-08-16

CVE-2021-24508

The Smash Balloon Social Post Feed plugin before version 2.19.2 contains a stored cross-site scripting vulnerability in its feed_locator AJAX action, which is accessible to both authenticated and unauthenticated users. The feedID POST parameter fails to undergo proper sanitization or escaping, allowing attackers to inject malicious scripts that are later displayed in the admin dashboard. When an administrator views this content, the injected code executes with their privileges, even though the initial attack requires no authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.