PLUGIN SECURITY

Is Instagram Feed safe?

Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.

What this plugin does

  • Slug: instagram-feed
  • Author: Syed Balkhi
  • 1000000+ active installs
  • 98/100 rating (4350 reviews on wordpress.org)
  • 52974708 all-time downloads
  • On WordPress.org since 2014-07-23

Instagraminstagram feedinstagram galleryinstagram photosInstagram widget

Maintenance status

  • Latest known version: 6.11.4
  • Last updated: 2026-08-25 3:52pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

3 known CVEs on file for Instagram Feed.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15452 Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 6.11.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.7 < 6.11.4 6.11.4 2026-08-04 ✓ fixed in latest
CVE-2026-12002 Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 6.11.2 Cross-Site Request Forgery (CSRF) Medium 4.7 < 6.11.2 6.11.2 2026-07-08 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 2.9.2 Unknown < 2.9.2 2.9.2 2021-07-20 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 1.12 Unknown < 1.12 1.12 2019-03-05 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 1.6 Unknown < 1.6 1.6 2018-02-07 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 1.6 Unknown < 1.6 1.6 2018-01-18 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 1.4.7 Unknown < 1.4.7 1.4.7 2016-11-21 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 1.4.7 Unknown < 1.4.7 1.4.7 2016-11-19 ✓ fixed in latest
+ 10 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 6.9.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 6.9.1 6.9.1 0000-00-00 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 2.9.2 Unknown < 2.9.2 2.9.2 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 1.12 Unknown < 1.12 1.12 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 1.6 Unknown < 1.6 1.6 ✓ fixed in latest
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 1.4.7 Unknown < 1.4.7 1.4.7 ✓ fixed in latest
Instagram Feed < 1.4.7 - Authenticated Cross-Site Scripting (XSS) & CSRF Unknown < 1.4.7 1.4.7 ✓ fixed in latest
Instagram Feed < 1.6 - Cross-Site Scripting (XSS) Unknown < 1.6 1.6 ✓ fixed in latest
Instagram Feed < 1.12 - Unspecified Issues Unknown < 1.12 1.12 ✓ fixed in latest
Multiple Plugins from Smash Balloon - Reflected Cross-Site Scripting Unknown < 2.9.2 2.9.2 ✓ fixed in latest
CVE-2025-4583 Smash Balloon Instagram Feed < 6.9.1 - Contributor+ Stored XSS via `data-plugin` Attribute Unknown < 6.9.1 6.9.1 ✓ fixed in latest

How to fix it

Keep Instagram Feed updated — 6.11.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.