CVE Database /
CVE-2024-31379
CVE · Medium
CVE-2024-31379 — Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.2.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-31379
|
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.2.2 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 4.2.2
|
4.2.2 |
2024-04-10 |
—
|
CVE-2024-31379
The Smash Balloon Social Post Feed plugin for WordPress contained a cross-site request forgery vulnerability that could enable attackers to trick authenticated administrators into performing unintended actions. Researcher Majed Refaea identified the flaw, which allowed malicious actors to exploit user sessions with elevated privileges. The vulnerability was resolved in version 4.2.2 and administrators should upgrade to this version or later to secure their installations.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings