Impact
A missing authorization check in the Smash Balloon Social Post Feed plugin jeopardizes user control over the plugin’s functionality, allowing attackers that lack proper privileges to gain unintended access. The vulnerability exposes the plugin to misuse, where an attacker could potentially view or alter content delivered by the plugin.
Affected Systems
WordPress sites that install the Shake Balloon Social Post Feed plugin from the Syed Balkhi vendor package. All releases up to and including version 4.3.2 are impacted; newer releases are not listed as affected.
Risk and Exploitability
The CVSS score of 4.3 places the issue in a moderate range, and the EPSS score of <1% indicates a very low current exploitation probability. Since the change is not catalogued in CISA’s KEV list, there is currently no evidence of active exploitation. The vulnerability can likely be leveraged through normal plugin interfaces where user authentication and role verification do not enforce proper boundaries.
OpenCVE Enrichment