PT-2026-56394 · WordPress · Smash Balloon Social Post Feed

·

CVE-2026-12002

·

Published

2026-07-08

·

Updated

2026-07-17

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Smash Balloon Social Photo Feed – Easy Social Feeds Plugin versions prior to 6.11.2
Description Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the maybe connection data() function. This allows unauthenticated attackers to overwrite Instagram and Facebook oEmbed access tokens using the sbi access token parameter by tricking a site administrator into clicking a malicious link. Nonce validation is a security measure used to ensure that a request was intentionally sent by the user and not forged by a third party.
Recommendations Update Smash Balloon Social Photo Feed – Easy Social Feeds Plugin to version 6.11.2 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12002

Affected Products

Smash Balloon Social Post Feed