CVE · Medium

CVE-2026-15452 — Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 6.11.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15452 Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 6.11.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.7 < 6.11.4 6.11.4 2026-08-04

CVE-2026-15452

The Smash Balloon Social Photo Feed plugin contains a security flaw affecting all versions prior to 6.11.4, which allows malicious code injection through the REQUEST_URI parameter due to inadequate input validation and output encoding mechanisms. This vulnerability enables attackers to embed arbitrary scripts in pages that are executed if users follow specific links, resulting in potential unauthorized actions or data manipulation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.