VendorsSmash Balloonsmash_balloon_social_post_feedall versions
Vulnerabilities

Smash Balloon Social Post Feed 4.1.6 for WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-24508
Smash Balloon Social Post Feed < 2.19.2 - Unauthenticated Stored XSS
Published 2021-09-13 · Modified
6.1EPSS 0.013
CVE-2021-25065
Smash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site Scripting (XSS)
Published 2022-01-17 · Modified
5.4EPSS 0.010
CVE-2021-24918
Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to Stored XSS
Published 2021-11-29 · Modified
5.4EPSS 0.007
CVE-2022-4477
Smash Balloon Social Post Feed < 4.1.6 - Contributor+ Stored XSS
Published 2023-01-16 · Modified
5.4EPSS 0.005