Description
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator accesses the feed builder preview page. This attack requires only a Facebook account to post a comment on the connected Facebook Page, with no WordPress credentials needed; additionally, the use of v-show rather than v-if means injected HTML — including onerror handlers — is evaluated in the DOM even when the comment section is not visually displayed. When combined with the lack of URL validation in the cff_install_addon AJAX handler (admin/addon-functions.php), an injected script running in an administrator's session can trigger arbitrary plugin installation from an attacker-controlled URL, which may result in server-side code execution.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The Smash Balloon Social Post Feed plugin for WordPress contains an unauthenticated stored cross‑site scripting flaw that lets an attacker insert malicious HTML and JavaScript via a Facebook comment message. The plugin renders these comments using a v‑html directive in the admin builder preview without proper input sanitization or output escaping, causing the script to execute in the browser of any administrator who opens the preview page. Because the injected script runs with the administrator’s privileges, it can reach backend AJAX handlers that lack URL validation and trigger the installation of arbitrary plugins from attacker‑controlled URLs, effectively turning a client‑side XSS into server‑side code execution.

Affected Systems

WordPress sites utilizing the Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin, versions up to and including 4.13.0, are affected. Any site that has the Builder Preview feature enabled for its social feeds can be compromised if it has not been upgraded to a later major release.

Risk and Exploitability

The flaw carries a CVSS score of 7.2, indicating a high severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires only a Facebook account to post a comment on the connected Facebook Page – no WordPress credentials are needed – and the exploitation only succeeds when an administrator visits the preview page. The absence of server‑side validation in an AJAX handler makes the XSS capable of triggering arbitrary plugin installation, which can lead to full server compromise.

Generated by OpenCVE AI on October 2, 2026 at 08:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Smash Balloon Social Post Feed to a release newer than 4.13.0, which removes the unsanitized v‑html output in the builder preview.
  • If an update cannot be applied immediately, temporarily disable the Builder Preview page or uninstall the plugin until a patched version is available to prevent the execution of injected scripts.
  • Review and cleanse existing Facebook comments on the site’s pages, deleting any that contain suspicious or injected code, and consider restricting comment posting to trusted users or disabling comments altogether as a temporary countermeasure.

Generated by OpenCVE AI on October 2, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator accesses the feed builder preview page. This attack requires only a Facebook account to post a comment on the connected Facebook Page, with no WordPress credentials needed; additionally, the use of v-show rather than v-if means injected HTML — including onerror handlers — is evaluated in the DOM even when the comment section is not visually displayed. When combined with the lack of URL validation in the cff_install_addon AJAX handler (admin/addon-functions.php), an injected script running in an administrator's session can trigger arbitrary plugin installation from an attacker-controlled URL, which may result in server-side code execution.
Title Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:27.358Z

Reserved: 2026-09-18T16:38:25.574Z

Link: CVE-2026-93756

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:03.240

Modified: 2026-10-02T08:17:03.240

Link: CVE-2026-93756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')