WordPress Plugin Vulnerabilities
Smash Balloon Social Photo Feed < 6.11.2 - Unauthenticated oEmbed Access Token Overwrite via CSRF
Description
The plugin is vulnerable to Cross-Site Request Forgery due to missing or incorrect nonce validation on the `maybe_connection_data` function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request, provided they can trick a site administrator into performing an action such as clicking a link.
Affects Plugins
References
Classification
Type
CSRF
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
normaandersonfrank
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-08 (about 1 month ago)
Added
2026-07-08 (about 1 month ago)
Last Updated
2026-07-08 (about 1 month ago)