CVE
CVE-2025-4577 — Smash Balloon Custom Facebook Feed < 4.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-4577 | Smash Balloon Custom Facebook Feed < 4.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute | — | Unknown | < 4.3.2 | 4.3.2 | — | — |
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.