Input validation vulnerability in Smash Balloon Social Post Feed – Simple Social Feeds for WordPress 4.3.1

The Smash Balloon Social Post Feed plugin for WordPress is not completely secure. This is because it does not properly clean and protect the data-color attribute, which can lead to a type of hacking called Stored Cross-Site Scripting. This allows people with certain levels of access to the website to insert harmful code into pages, which can then be executed when someone visits that page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.