cleantalk
Vulnerabilities and Security Researches

Smash Balloon Social Photo Feed – Best Social Feed Plugin for WordPress, 186f32c07afa9283cdfb606de43cacac95ab248f

Published on
Nov 19, 2016
Research Description
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 1.4.7 Smash Balloon Social Photo Feed <= 1.4.6.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting The Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in the settings page in versions up to, and including, 1.4.6.2 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.4.7.
Status
vulnerable