VulnerabilityModified
CVE-2021-24918
As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
MEDIUM 5.4EPSS 0.65%
Does this matter?
Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.
Description
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- smashballoon/smash balloon social post feed
- Source
- contact@wpscan.com
References
- https://jetpack.com/2021/10/29/security-issues-patched-in-smash-balloon-social-post-feed-plugin/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/5d252ad7-bf28-44f3-8cd0-c4fe05c48f35Third Party Advisory
- https://jetpack.com/2021/10/29/security-issues-patched-in-smash-balloon-social-post-feed-plugin/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/5d252ad7-bf28-44f3-8cd0-c4fe05c48f35Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.