MEDIUM
Smash Balloon
CVE published 2026-08-05
CVE-2026-15452
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query String in all versions up to, and including, 6.11.3. This vulnerability is caused by insufficient input sanitization and output escaping. The CVE record was published on 2026-08-05T10:17:27.110Z and has not been modified since then. Evidence is limited to CVE a [truncated]