Impact
The Smash Balloon Social Post Feed plugin for WordPress contains an unauthenticated stored cross‑site scripting flaw that lets an attacker insert malicious HTML and JavaScript via a Facebook comment message. The plugin renders these comments using a v‑html directive in the admin builder preview without proper input sanitization or output escaping, causing the script to execute in the browser of any administrator who opens the preview page. Because the injected script runs with the administrator’s privileges, it can reach backend AJAX handlers that lack URL validation and trigger the installation of arbitrary plugins from attacker‑controlled URLs, effectively turning a client‑side XSS into server‑side code execution.
Affected Systems
WordPress sites utilizing the Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin, versions up to and including 4.13.0, are affected. Any site that has the Builder Preview feature enabled for its social feeds can be compromised if it has not been upgraded to a later major release.
Risk and Exploitability
The flaw carries a CVSS score of 7.2, indicating a high severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires only a Facebook account to post a comment on the connected Facebook Page – no WordPress credentials are needed – and the exploitation only succeeds when an administrator visits the preview page. The absence of server‑side validation in an AJAX handler makes the XSS capable of triggering arbitrary plugin installation, which can lead to full server compromise.
OpenCVE Enrichment