Stored Cross-Site Scripting and RCE in Smash Balloon Social Post Feed
The Smash Balloon Social Post Feed WordPress plugin is vulnerable to Stored XSS that can be escalated to arbitrary plugin installation and remote code execution.
CVE search metadata
CVE search record: CVE-2026-93756. Severity: high. CVSS: 7.2. KEV: no. Product: Social Post Feed – Simple Social Feeds for WordPress (<= 4.13.0). Brief: Stored Cross-Site Scripting and RCE in Smash Balloon Social Post Feed. Brief link: https://feed.craftedsignal.io/briefs/2026-10-smash-balloon-xss/
The Smash Balloon Social Post Feed (all versions up to and including 4.13.0) contains a critical security vulnerability involving insufficient input sanitization and output escaping. An unauthenticated attacker can perform a Stored Cross-Site Scripting (XSS) attack by posting a crafted message to a Facebook Page connected to the WordPress plugin. Because the plugin's Admin Builder Preview uses the v-show directive rather than v-if, injected HTML and JavaScript (such as onerror handlers) are rendered and executed in the administrator's browser context even when the content is hidden. Furthermore, this vulnerability can be chained with an insecure AJAX handler (cff_install_addon) in admin/addon-functions.php, which lacks URL validation. By forcing an authenticated administrator to interact with the feed builder, an attacker can leverage the XSS payload to trigger the installation of arbitrary, malicious plugins from an external URL, ultimately leading to server-side code execution.
Attack Chain
- Attacker posts a comment containing a malicious JavaScript payload to a Facebook Page connected to a target WordPress site.
- The plugin synchronizes the malicious comment from Facebook into the WordPress database without sanitization.
- A site administrator logs into the WordPress dashboard and navigates to the Social Post Feed plugin's Admin Builder Preview.
- The plugin renders the malicious comment content in the DOM via the vulnerable v-show directive.
- The injected JavaScript payload executes in the administrator's session.
- The payload makes an AJAX request to the cff_install_addon handler (admin/addon-functions.php).
- The handler processes the request using an attacker-supplied external URL to fetch and install a malicious plugin.
- The malicious plugin is activated, granting the attacker full remote code execution on the WordPress server.
Impact
Successful exploitation allows unauthenticated attackers to achieve remote code execution on the underlying server. This enables full site compromise, data exfiltration, and the ability to pivot into the host environment. All WordPress sites using the Social Post Feed plugin version 4.13.0 or earlier are susceptible to this vector.
Recommendation
- Immediately update the Social Post Feed - Simple Social Feeds for WordPress plugin to a version beyond 4.13.0 that addresses the sanitization and URL validation flaws.
- Implement an aggressive Web Application Firewall (WAF) rule to block POST requests containing suspicious JavaScript strings or unexpected external URLs directed at the cff_install_addon AJAX endpoint.
- Audit the WordPress administrative activity logs for unexpected plugin installations or activations, specifically looking for sources outside the official WordPress.org repository.
Immediate actions
Upgrade Social Post Feed plugin to version > 4.13.0
Mitigations
Block or filter requests to cff_install_addon on the web server
CVE-2026-93756
Detection coverage 1
Detect CVE-2026-93756 Exploitation - Unauthorized Plugin Installation Attempt
highDetects potential exploitation attempts by monitoring requests to the cff_install_addon AJAX endpoint which lacks input validation for the source URL.
Detection queries are available on the platform. Get full rules →