SecAlerts
smashballoon logo

smashballoon

Security Risk Profile

32
/100
low

Security Risk Score

Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 13, 2021 to present

13
Total CVEs
3
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
32/100
low

Severity Distribution

Critical
0
High
3
Medium
10
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
5

Age Distribution

Common Weaknesses (CWE)

1
XSS
7
2
CSRF
5
3
Command Injection
1

Most Affected Products

1. Smashballoon Custom Twitter Feeds Wordpress5
2. Smashballoon Smash Balloon Social Post Feed Wordpress4
3. Smashballoon Reviews Feed Wordpress2
4. Smashballoon Feeds For Youtube Wordpress2
5. Smash Balloon Custom Twitter Feeds1

Recent Vulnerabilities

See more →
CVE-2024-49685
CVSS 8.8EPSS 0%high

WordPress Custom Twitter Feeds plugin <= 2.2.3 - Cross Site Request Forgery (CSRF) vulnerability

10/31/2024
CVE-2024-8983
CVSS 4.8EPSS 0%medium

Custom Twitter Feeds < 2.2.3 - Admin+ Stored XSS

10/8/2024🔧 No Patch
CVE-2024-8199
CVSS 4.3EPSS 0%medium

Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update

8/27/2024
CVE-2024-8200
CVSS 4.3EPSS 0%medium

Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Cross-Site Request Forgery

8/27/2024
CVE-2024-6256
CVSS 6.4EPSS 0%medium

Feeds for YouTube (YouTube video, channel, and gallery plugin) <= 2.2.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

7/11/2024🔧 No Patch
CVE-2024-0379
CVSS 4.3medium

Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Update

2/20/2024
CVE-2023-52136
CVSS 8.8high

WordPress Custom Twitter Feeds (Tweets Widget) Plugin <= 2.1.2 is vulnerable to Cross Site Request Forgery (CSRF)

1/5/2024
CVE-2023-4841
CVSS 6.4medium

Feeds for YouTube <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

9/14/2023
CVE-2022-33974
CVSS 8.8high

WordPress Custom Twitter Feeds (Tweets Widget) Plugin <= 1.8.4 is vulnerable to Cross Site Request Forgery (CSRF)

5/29/2023
CVE-2022-4477
CVSS 5.4medium

Smash Balloon Social Post Feed < 4.1.6 - Contributor+ Stored XSS

1/16/2023🔧 No Patch

Monitor smashballoon in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.