CVE

CVE-2025-4577 — Smash Balloon Custom Facebook Feed < 4.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-4577 Smash Balloon Custom Facebook Feed < 4.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute Unknown < 4.3.2 4.3.2

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.