Smash Balloon Social Post Feed, 63d036bf8354801dd02167b4cc6a671f96fb03ce
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jul 20, 2021
- Research Description
- Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 2.19.2 Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting Several Smash Balloon Plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via URLs in various versions due to insufficient input sanitization and output escaping with the use of add_query_arg. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 2.19.2.
- Status
-
vulnerable