Executive brief
The Smash Balloon Social Photo Feed plugin for WordPress, which is used to display Instagram and Facebook content on websites, contains a security flaw that could allow an attacker to disrupt social media integrations. By tricking a site administrator into clicking a malicious link, an attacker can overwrite the site's social media access tokens. This would cause social media feeds or embedded content to stop working correctly on the affected website.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Smash Balloon Social Photo Feed plugin due to missing or incorrect nonce validation in the 'maybe_connection_data' function within the SBI_oEmbeds.php component. An unauthenticated attacker can exploit this by crafting a malicious request and inducing a site administrator to execute it (e.g., via social engineering or a phishing link). Successful exploitation allows the attacker to overwrite the site's Instagram and Facebook oEmbed access tokens, leading to a loss of integrity for social media integrations. The issue affects all versions up to 6.11.1; users should update to a patched version if available.
Affected products
- Smash Balloon Smash Balloon Social Photo Feed – Easy Social Feeds Plugin up to, and including, 6.11.1
Timeline
- 2026-07-08: disclosed: CVE published by Wordfence/NVD