Description
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2026-07-08
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin suffers from a missing or incorrect nonce check in its maybe_connection_data function, a Cross‑Site Request Forgery (CWE‑352) vulnerability that allows a forged request to modify the site's Instagram and Facebook oEmbed access tokens. This flaw permits an unauthenticated attacker to overwrite the credentials used for embedding social media content, potentially leading to loss of control over social feed integration and exposure of sensitive token data.

Affected Systems

Any WordPress site using the Smash Balloon Social Photo Feed – Easy Social Feeds Plugin from version 6.11.1 and earlier is affected. The vulnerability is tied to the smub vendor and does not depend on a specific WordPress core version; all installations with the vulnerable plugin are considered at risk.

Risk and Exploitability

The flaw carries a CVSS score of 4.7, indicating moderate severity. The EPSS score is less than 1%, suggesting a very low but non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The attack most likely involves a administrator is tricked into clicking a malicious link a forged 'sbi_access_token' parameter, bypassing the missing nonce validation and triggering the token overwrite.

Generated by OpenCVE AI on July 29, 2026 at 14:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Smash Balloon Social Photo Feed – Easy Social Feeds Plugin to the latest available version, which resolves the Cross‑Site Request Forgery (CWE‑352) vulnerability by adding proper nonce validation.
  • If a patch cannot be applied immediately, restrict access to the plugin’s admin pages from trusted origins only and consider disabling the oEmbed token management feature until the update is installed.
  • After applying a patch or workaround, verify the integrity of the Instagram and Facebook oEmbed access tokens and reset them if necessary to eliminate any tokens that may have been replaced by an attacker.

Generated by OpenCVE AI on July 29, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Smub
Smub smash Balloon Social Photo Feed – Easy Social Feeds Plugin
Wordpress
Wordpress wordpress
Vendors & Products Smub
Smub smash Balloon Social Photo Feed – Easy Social Feeds Plugin
Wordpress
Wordpress wordpress

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


Subscriptions

Smub Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-08T13:03:04.692Z

Reserved: 2026-06-11T16:59:38.484Z

Link: CVE-2026-12002

cve-icon Vulnrichment

Updated: 2026-07-08T13:03:00.524Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:30:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)