All 6 CVE vulnerabilities found in Smash Balloon Social Post Feed, with AI-generated Chinese analysis, references, and POCs.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-49937 | WordPress Smash Balloon Social Post Feed plugin <= 4.3.2 - Broken Access Control vulnerability CWE-862 | 4.3 | Medium | 2025-10-22 |
| CVE-2024-31379 | WordPress Smash Balloon Social Post Feed plugin <= 4.2.1 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 | 4.3 | Medium | 2024-04-15 |
| CVE-2022-4477 | Smash Balloon Social Post Feed < 4.1.6 - Contributor+ Stored XSS | 5.4 | - | 2023-01-16 |
| CVE-2021-25065 | Smash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site Scripting (XSS) CWE-79 | 5.4 | - | 2022-01-17 |
| CVE-2021-24918 | Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to Stored XSS CWE-79 | 5.4 | - | 2021-11-29 |
| CVE-2021-24508 | Smash Balloon Social Post Feed < 2.19.2 - Unauthenticated Stored XSS CWE-79 | 6.1 | - | 2021-09-13 |
All 6 known CVE vulnerabilities affecting Smash Balloon Social Post Feed with full Chinese analysis, references, and POCs where available.