Impact
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin suffers from a missing or incorrect nonce check in its maybe_connection_data function, a Cross‑Site Request Forgery (CWE‑352) vulnerability that allows a forged request to modify the site's Instagram and Facebook oEmbed access tokens. This flaw permits an unauthenticated attacker to overwrite the credentials used for embedding social media content, potentially leading to loss of control over social feed integration and exposure of sensitive token data.
Affected Systems
Any WordPress site using the Smash Balloon Social Photo Feed – Easy Social Feeds Plugin from version 6.11.1 and earlier is affected. The vulnerability is tied to the smub vendor and does not depend on a specific WordPress core version; all installations with the vulnerable plugin are considered at risk.
Risk and Exploitability
The flaw carries a CVSS score of 4.7, indicating moderate severity. The EPSS score is less than 1%, suggesting a very low but non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The attack most likely involves a administrator is tricked into clicking a malicious link a forged 'sbi_access_token' parameter, bypassing the missing nonce validation and triggering the token overwrite.
OpenCVE Enrichment