Stored Cross-Site Scripting in Smash Balloon Social Post Feed for WordPress
CVE-2026-93756

7.2HIGH

What is CVE-2026-93756?

The Smash Balloon Social Post Feed plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. An attacker can exploit this weakness by injecting arbitrary scripts into Facebook comment messages, which are executed when an administrator views the feed builder preview page. Notably, the vulnerability does not require WordPress credentials, only a Facebook account to comment on the linked page. Further compounding the risk, the plugin's use of v-show over v-if enables unauthorized scripts to execute even when the comment section is hidden. Additionally, the lack of URL validation in the cff_install_addon AJAX handler allows scripts running in the admin's session to trigger malicious plugin installations from compromised URLs, potentially leading to server-side code execution.

Affected Version(s)

Smash Balloon Social Post Feed – Simple Social Feeds for WordPress 0 <= 4.13.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuto Hyakumoto
.