Extension WordPress
Vulnérabilités Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
Cette page rassemble les failles publiées pour Smash Balloon Social Post Feed – Simple Social Feeds for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
8 fiches
Smash Balloon Social Post Feed <= 4.3.2 – Missing Authorization
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.3.2. This…
*-4.3.2
4.3.3
09/10/2025
Smash Balloon Custom Facebook Feed <= 4.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` Attribute
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-color attribute in all versions up to, and including, 4.3.1 due to insufficient input sanitization…
*-4.3.1
4.3.2
09/06/2025
Smash Balloon Social Post Feed <= 4.2.1 – Cross-Site Request Forgery
The Smash Balloon Social Post Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.1. This is due to missing or incorrect nonce validation on the maybe_source_connection_data() function. This makes it…
*-4.2.1
4.2.2
10/04/2024
Smash Balloon Social Post Feed <= 4.1.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Smash Balloon Social Post Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-4.1.5
4.1.6
20/12/2022
Smash Balloon Social Post Feed <= 4.1 – Reflected Cross-Site Scripting
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
[*, 4.1.1)
4.1.1
16/12/2021
Smash Balloon Social Post Feed <= 4.0 – Arbitrary Plugin Settings Update to Stored Cross-Site Scripting
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and…
[*, 4.0.1)
4.0.1
29/10/2021
Smash Balloon Social Post Feed <= 2.19.1 – Unauthenticated Stored Cross-Site Scripting
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it…
[*, 2.19.2)
2.19.2
16/08/2021
Smash Balloon Plugins (Various Versions) – Reflected Cross-Site Scripting
Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to…
*-2.19.1
2.19.2
20/07/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.