Stored Cross-Site Scripting in Smash Balloon Social Post Feed for WordPress
CVE-2026-93756
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-93756?
The Smash Balloon Social Post Feed plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. An attacker can exploit this weakness by injecting arbitrary scripts into Facebook comment messages, which are executed when an administrator views the feed builder preview page. Notably, the vulnerability does not require WordPress credentials, only a Facebook account to comment on the linked page. Further compounding the risk, the plugin's use of v-show over v-if enables unauthorized scripts to execute even when the comment section is hidden. Additionally, the lack of URL validation in the cff_install_addon AJAX handler allows scripts running in the admin's session to trigger malicious plugin installations from compromised URLs, potentially leading to server-side code execution.
Affected Version(s)
Smash Balloon Social Post Feed β Simple Social Feeds for WordPress 0 <= 4.13.0