CVE-2026-15452: Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query String
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUESTURI Query String in all versions up to, and including, 6.11.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15452?
The severity of CVE-2026-15452 is classified as medium with a CVSS score of 4.7.
How do I fix CVE-2026-15452?
To fix CVE-2026-15452, update the Smash Balloon Social Photo Feed plugin to version 6.11.4 or later.
What type of vulnerability is CVE-2026-15452?
CVE-2026-15452 is a reflected cross-site scripting (XSS) vulnerability.
What plugin is affected by CVE-2026-15452?
CVE-2026-15452 affects the Smash Balloon Social Photo Feed – Easy Social Feeds Plugin for WordPress.
When was CVE-2026-15452 published?
CVE-2026-15452 was published on August 5, 2026.