Description
WordPress Plugin Smash Balloon Social Post Feed is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugin's settings. WordPress Plugin Smash Balloon Social Post Feed version 4.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0.1 or latest
References
https://jetpack.com/2021/10/29/security-issues-patched-in-smash-balloon-social-post-feed-plugin/
https://plugins.svn.wordpress.org/custom-facebook-feed/trunk/README.txt
Related Vulnerabilities
WordPress Plugin Responsive WordPress Slider Cross-Site Scripting (2.2.0)
WordPress Plugin 123devis-affiliation Cross-Site Scripting (1.0.4)
WordPress 5.8.x Multiple Vulnerabilities (5.8 - 5.8.7)
WordPress Plugin Timber Cross-Site Scripting (1.2.2)
Zope Web Application Server Other Vulnerability (CVE-2000-0062)