CVE · Medium

CVE-2024-31379 — Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-31379 Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.2.2 Cross-Site Request Forgery (CSRF) Medium 4.3 < 4.2.2 4.2.2 2024-04-10

CVE-2024-31379

The Smash Balloon Social Post Feed plugin for WordPress contained a cross-site request forgery vulnerability that could enable attackers to trick authenticated administrators into performing unintended actions. Researcher Majed Refaea identified the flaw, which allowed malicious actors to exploit user sessions with elevated privileges. The vulnerability was resolved in version 4.2.2 and administrators should upgrade to this version or later to secure their installations.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.