Reflected Cross-Site Scripting Vulnerability in Smash Balloon Social Photo Feed Plugin
CVE-2026-15452
4.7MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-15452?
The Smash Balloon Social Photo Feed Plugin for WordPress is susceptible to a reflected cross-site scripting vulnerability due to inadequate input validation and output escaping. This oversight allows attackers to exploit the REQUEST_URI query string, enabling them to inject malicious scripts that could execute in the context of the user's session. If an attacker can persuade a user to click on a crafted link, they can potentially manipulate the affected pages, leading to unauthorized actions and data exposure.
Affected Version(s)
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin 0 <= 6.11.3