WordPress Plugin Vulnerabilities

Smash Balloon Social Photo Feed < 6.11.2 - Unauthenticated oEmbed Access Token Overwrite via CSRF

Description

The plugin is vulnerable to Cross-Site Request Forgery due to missing or incorrect nonce validation on the `maybe_connection_data` function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request, provided they can trick a site administrator into performing an action such as clicking a link.

Affects Plugins

Fixed in 6.11.2

References

Classification

Miscellaneous

Original Researcher
normaandersonfrank
Verified
No

Timeline

Publicly Published
2026-07-08 (about 1 month ago)
Added
2026-07-08 (about 1 month ago)
Last Updated
2026-07-08 (about 1 month ago)

Other