Missing Authorization in Smash Balloon Social Post Feed by Syed Balkhi
CVE-2025-49937

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2025

What is CVE-2025-49937?

A missing authorization vulnerability exists in the Smash Balloon Social Post Feed plugin, developed by Syed Balkhi, due to incorrectly configured access control security levels. This flaw allows unauthorized users to exploit the plugin's functionality, potentially leading to unauthorized access to sensitive data and actions. The vulnerability impacts versions from n/a up to and including 4.3.2, making it crucial for users of this plugin to remain vigilant and update to secure versions promptly.

Affected Version(s)

Smash Balloon Social Post Feed <= n/a

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter (Patchstack Alliance)
.