Description
WordPress Plugin Smash Balloon Social Post Feed is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugin's settings. WordPress Plugin Smash Balloon Social Post Feed version 4.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0.1 or latest
References
https://jetpack.com/2021/10/29/security-issues-patched-in-smash-balloon-social-post-feed-plugin/
https://plugins.svn.wordpress.org/custom-facebook-feed/trunk/README.txt
Related Vulnerabilities
WordPress Plugin Cross-RSS Directory Traversal (1.7)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17310)
MySQL CVE-2014-2442 Vulnerability (CVE-2014-2442)
WeBid Other Vulnerability (CVE-2014-5114)
WordPress Plugin Let Them Unsubscribe Multiple Unspecified Vulnerabilities (1.0)