Reflected Cross-Site Scripting Vulnerability in Smash Balloon Social Photo Feed Plugin
CVE-2026-15452

4.7MEDIUM

What is CVE-2026-15452?

The Smash Balloon Social Photo Feed Plugin for WordPress is susceptible to a reflected cross-site scripting vulnerability due to inadequate input validation and output escaping. This oversight allows attackers to exploit the REQUEST_URI query string, enabling them to inject malicious scripts that could execute in the context of the user's session. If an attacker can persuade a user to click on a crafted link, they can potentially manipulate the affected pages, leading to unauthorized actions and data exposure.

Affected Version(s)

Smash Balloon Social Photo Feed – Easy Social Feeds Plugin 0 <= 6.11.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tarcísio Luchesi De Almeida Silva (Poystick)
.