CVE Database /
CVE-2026-15452
CVE · Medium
CVE-2026-15452 — Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 6.11.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-15452
|
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 6.11.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.7
|
< 6.11.4
|
6.11.4 |
2026-08-04 |
—
|
CVE-2026-15452
The Smash Balloon Social Photo Feed plugin contains a security flaw affecting all versions prior to 6.11.4, which allows malicious code injection through the REQUEST_URI parameter due to inadequate input validation and output encoding mechanisms. This vulnerability enables attackers to embed arbitrary scripts in pages that are executed if users follow specific links, resulting in potential unauthorized actions or data manipulation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings