Extension WordPress

Vulnérabilités Smash Balloon Social Post Feed – Simple Social Feeds for WordPress

Cette page rassemble les failles publiées pour Smash Balloon Social Post Feed – Simple Social Feeds for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Smash Balloon Social Post Feed – Simple Social Feeds for WordPress

8 fiches

CVE-2025-4577 Moyenne · 6,4
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress

Smash Balloon Custom Facebook Feed <= 4.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-color attribute in all versions up to, and including, 4.3.1 due to insufficient input sanitization…

Versions affectées

*-4.3.1

Correctif

4.3.2

Publication

09/06/2025

CVE-2024-31379 Moyenne · 4,3
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress

Smash Balloon Social Post Feed <= 4.2.1 – Cross-Site Request Forgery

The Smash Balloon Social Post Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.1. This is due to missing or incorrect nonce validation on the maybe_source_connection_data() function. This makes it…

Versions affectées

*-4.2.1

Correctif

4.2.2

Publication

10/04/2024

CVE-2022-4477 Moyenne · 6,4
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress

Smash Balloon Social Post Feed <= 4.1.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Smash Balloon Social Post Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-4.1.5

Correctif

4.1.6

Publication

20/12/2022

CVE-2021-24918 Moyenne · 5,4
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress

Smash Balloon Social Post Feed <= 4.0 – Arbitrary Plugin Settings Update to Stored Cross-Site Scripting

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and…

Versions affectées

[*, 4.0.1)

Correctif

4.0.1

Publication

29/10/2021

CVE-2021-24508 Moyenne · 6,1
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress

Smash Balloon Social Post Feed <= 2.19.1 – Unauthenticated Stored Cross-Site Scripting

The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it…

Versions affectées

[*, 2.19.2)

Correctif

2.19.2

Publication

16/08/2021

Vulnérabilité Moyenne · 6,1
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress

Smash Balloon Plugins (Various Versions) – Reflected Cross-Site Scripting

Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.19.1

Correctif

2.19.2

Publication

20/07/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités