PT-2026-56394 · WordPress · Smash Balloon Social Post Feed
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin versions prior to 6.11.2
Description
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the
maybe connection data() function. This allows unauthenticated attackers to overwrite Instagram and Facebook oEmbed access tokens using the sbi access token parameter by tricking a site administrator into clicking a malicious link. Nonce validation is a security measure used to ensure that a request was intentionally sent by the user and not forged by a third party.Recommendations
Update Smash Balloon Social Photo Feed – Easy Social Feeds Plugin to version 6.11.2 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smash Balloon Social Post Feed