{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/smash-balloon/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:smashballoon:social_post_feed:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-93756"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Social Post Feed – Simple Social Feeds for WordPress (\u003c= 4.13.0)"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","rce","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Smash Balloon"],"content_html":"\u003cp\u003eThe Smash Balloon Social Post Feed (all versions up to and including 4.13.0) contains a critical security vulnerability involving insufficient input sanitization and output escaping. An unauthenticated attacker can perform a Stored Cross-Site Scripting (XSS) attack by posting a crafted message to a Facebook Page connected to the WordPress plugin. Because the plugin's Admin Builder Preview uses the v-show directive rather than v-if, injected HTML and JavaScript (such as onerror handlers) are rendered and executed in the administrator's browser context even when the content is hidden. Furthermore, this vulnerability can be chained with an insecure AJAX handler (cff_install_addon) in admin/addon-functions.php, which lacks URL validation. By forcing an authenticated administrator to interact with the feed builder, an attacker can leverage the XSS payload to trigger the installation of arbitrary, malicious plugins from an external URL, ultimately leading to server-side code execution.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker posts a comment containing a malicious JavaScript payload to a Facebook Page connected to a target WordPress site.\u003c/li\u003e\n\u003cli\u003eThe plugin synchronizes the malicious comment from Facebook into the WordPress database without sanitization.\u003c/li\u003e\n\u003cli\u003eA site administrator logs into the WordPress dashboard and navigates to the Social Post Feed plugin's Admin Builder Preview.\u003c/li\u003e\n\u003cli\u003eThe plugin renders the malicious comment content in the DOM via the vulnerable v-show directive.\u003c/li\u003e\n\u003cli\u003eThe injected JavaScript payload executes in the administrator's session.\u003c/li\u003e\n\u003cli\u003eThe payload makes an AJAX request to the cff_install_addon handler (admin/addon-functions.php).\u003c/li\u003e\n\u003cli\u003eThe handler processes the request using an attacker-supplied external URL to fetch and install a malicious plugin.\u003c/li\u003e\n\u003cli\u003eThe malicious plugin is activated, granting the attacker full remote code execution on the WordPress server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to achieve remote code execution on the underlying server. This enables full site compromise, data exfiltration, and the ability to pivot into the host environment. All WordPress sites using the Social Post Feed plugin version 4.13.0 or earlier are susceptible to this vector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the Social Post Feed - Simple Social Feeds for WordPress plugin to a version beyond 4.13.0 that addresses the sanitization and URL validation flaws.\u003c/li\u003e\n\u003cli\u003eImplement an aggressive Web Application Firewall (WAF) rule to block POST requests containing suspicious JavaScript strings or unexpected external URLs directed at the cff_install_addon AJAX endpoint.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress administrative activity logs for unexpected plugin installations or activations, specifically looking for sources outside the official WordPress.org repository.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T08:23:46Z","date_published":"2026-10-02T08:23:46Z","id":"https://feed.craftedsignal.io/briefs/2026-10-smash-balloon-xss/","summary":"The Smash Balloon Social Post Feed WordPress plugin is vulnerable to Stored XSS that can be escalated to arbitrary plugin installation and remote code execution.","title":"Stored Cross-Site Scripting and RCE in Smash Balloon Social Post Feed","url":"https://feed.craftedsignal.io/briefs/2026-10-smash-balloon-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Smash Balloon","version":"https://jsonfeed.org/version/1.1"}