Smashballoon develops a suite of WordPress plugins for embedding and displaying social media feeds and reviews, with a recurring vulnerability profile concentrated in its Custom Twitter Feeds, Social Post Feed, Feeds for YouTube, and Reviews Feed products. The durable signal across these plugins centers on web-application input-handling and authorization weaknesses—cross-site request forgery, cross-site scripting, command injection, and missing authorization controls—typical of server-side plugins that process and render user-supplied and external content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smashballoon over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25065MEDIUM The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page. | Jan 17, 2022 | 5.4 | 30 | NO | YES |
CVE-2022-33974HIGH Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions. | May 29, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-49685HIGH Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Forgery.This issue affects Custom | Oct 31, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-52136HIGH Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget o | Jan 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2021-24508MEDIUM The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authentic | Sep 13, 2021 | 6.1 | 21 | NO | NO |
CVE-2022-4477MEDIUM The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could | Jan 16, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-4841MEDIUM The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in versions up to, and including, 2.1 due to insufficient input | Sep 14, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-24918MEDIUM The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user | Nov 29, 2021 | 5.4 | 19 | NO | NO |
CVE-2024-8200MEDIUM The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve | Aug 27, 2024 | 4.3 | 17 | NO | NO |
CVE-2024-6256MEDIUM The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in al | Jul 11, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smashballoon.
Media articles that mention a CVE ID that affects a product developed by Smashballoon — matched by CVE ID, not by vendor name.