<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Smash Balloon - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/smash-balloon/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 08:23:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/smash-balloon/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting and RCE in Smash Balloon Social Post Feed</title><link>https://feed.craftedsignal.io/briefs/2026-10-smash-balloon-xss/</link><pubDate>Fri, 02 Oct 2026 08:23:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-smash-balloon-xss/</guid><description>The Smash Balloon Social Post Feed WordPress plugin is vulnerable to Stored XSS that can be escalated to arbitrary plugin installation and remote code execution.</description><content:encoded><![CDATA[<p>The Smash Balloon Social Post Feed (all versions up to and including 4.13.0) contains a critical security vulnerability involving insufficient input sanitization and output escaping. An unauthenticated attacker can perform a Stored Cross-Site Scripting (XSS) attack by posting a crafted message to a Facebook Page connected to the WordPress plugin. Because the plugin's Admin Builder Preview uses the v-show directive rather than v-if, injected HTML and JavaScript (such as onerror handlers) are rendered and executed in the administrator's browser context even when the content is hidden. Furthermore, this vulnerability can be chained with an insecure AJAX handler (cff_install_addon) in admin/addon-functions.php, which lacks URL validation. By forcing an authenticated administrator to interact with the feed builder, an attacker can leverage the XSS payload to trigger the installation of arbitrary, malicious plugins from an external URL, ultimately leading to server-side code execution.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker posts a comment containing a malicious JavaScript payload to a Facebook Page connected to a target WordPress site.</li>
<li>The plugin synchronizes the malicious comment from Facebook into the WordPress database without sanitization.</li>
<li>A site administrator logs into the WordPress dashboard and navigates to the Social Post Feed plugin's Admin Builder Preview.</li>
<li>The plugin renders the malicious comment content in the DOM via the vulnerable v-show directive.</li>
<li>The injected JavaScript payload executes in the administrator's session.</li>
<li>The payload makes an AJAX request to the cff_install_addon handler (admin/addon-functions.php).</li>
<li>The handler processes the request using an attacker-supplied external URL to fetch and install a malicious plugin.</li>
<li>The malicious plugin is activated, granting the attacker full remote code execution on the WordPress server.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to achieve remote code execution on the underlying server. This enables full site compromise, data exfiltration, and the ability to pivot into the host environment. All WordPress sites using the Social Post Feed plugin version 4.13.0 or earlier are susceptible to this vector.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately update the Social Post Feed - Simple Social Feeds for WordPress plugin to a version beyond 4.13.0 that addresses the sanitization and URL validation flaws.</li>
<li>Implement an aggressive Web Application Firewall (WAF) rule to block POST requests containing suspicious JavaScript strings or unexpected external URLs directed at the cff_install_addon AJAX endpoint.</li>
<li>Audit the WordPress administrative activity logs for unexpected plugin installations or activations, specifically looking for sources outside the official WordPress.org repository.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>xss</category><category>rce</category><category>web-application-vulnerability</category></item></channel></rss>