cleantalk
Vulnerabilities and Security Researches

Smash Balloon Social Post Feed, CVE-2021-24918

CVE, Research URL

CVE-2021-24918

Published on
Nov 29, 2021
Research Description
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
Affected versions
max 4.0.1.
Status
vulnerable