
CVE-2021-24508: WordPress Smash Balloon Plugin XSS Vulnerability (Cross-platform)
Stored Cross-Site Scripting (XSS) in Social Post Feed Plugin (< v2.19.2)
📢 Advisory Summary
Vulnerability Type: Stored XSS (CWE-79)
Affected Plugin: Smash Balloon Social Post Feed
Versions Impacted: < 2.19.2
CVSSv3 Score: 6.1 (Medium) [AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N]
Attack Vector: Authenticated users (Contributor+)
🔍 Technical Impact
Malicious actors could:
✓ Inject arbitrary JavaScript via Instagram feed embeds
✓ Hijack admin sessions when viewed in dashboard
✓ Deface sites or redirect users
🛡️ Mitigation Steps
Immediate Action:
Upgrade to Smash Balloon Social Post Feed ≥ v2.19.2
Audit user roles (limit Contributor privileges)
Detection:
SQL :
SELECT * FROM wp_posts WHERE post_content LIKE '%[instagram-feed%';
Temporary Measure:
Remove [instagram-feed] shortcodes until patched
📌 Vendor Response
Patch Released: July 2021 (v2.19.2)
Changelog Reference: Fixed XSS in feed customization
📚 Additional Resources
#WordPressSecurity #XSS #WebSecurity #PatchManagement
Similar
-
CVE-2024-29849 Critical Authentication Bypass in Veeam Backup Enterprise Manager CVE-2024-29849 Critical Authentication Bypass in Veeam Backup Enterprise Manager 2024-29849 (Linux)
-
CVE-2024-7954: Critical RCE in SPIP's Porte Plume Plugin CVE-2024-7954: Critical RCE in SPIP's Porte Plume Plugin 2024-7954 (Cross-platform)
-
CVE-2024-22567: Security Advisory for MCMS 5.3.5 CVE-2024-22567: Security Advisory for MCMS 5.3.5 2024-22567 (Cross-platform)
-
CVE-2024-11616: Buffer Overflow in Netskope Endpoint DLP CVE-2024-11616: Buffer Overflow in Netskope Endpoint DLP 2024-11616 (Cross-platform)
Top Softwares
-
CVE-2021-24508: WordPress Smash Balloon Plugin XSS Vulnerability CVE-2021-24508: WordPress Smash Balloon Plugin XSS Vulnerability 2021-24508 (Cross-platform)
-
App Builder (x64) – Complete Application Development Suite App Builder (x64) – Complete Application Development Suite 2025.7 (64-bit)
-
Opera Opera 32.1 (64-bit)
-
EE - Videohive - Text Number MOGRT EE - Videohive - Text Number MOGRT 58123788 (Cross-platform)
-
WinRAR for Windows WinRAR for Windows 1.9 (64-bit)
Featured
-
🕷️ Zeus RAT 2025 — Legacy of the Infamous Banking Trojan & Modern Threats 🕷️ Zeus RAT 2025 — Legacy of the Infamous Banking Trojan & Modern Threats Latest (64-bit)
-
🛠️ sqlMapGUI 2.0 — User-Friendly SQL Injection & Database Vulnerability Tool 🚀 🛠️ sqlMapGUI 2.0 — User-Friendly SQL Injection & Database Vulnerability Tool 🚀 Latest (64-bit)
-
💻 SSH RAT Keylogger Crypter 2025 — Ultimate Remote Access & Stealth Tool 🛡️ 💻 SSH RAT Keylogger Crypter 2025 — Ultimate Remote Access & Stealth Tool 🛡️ Latest (64-bit)
-
🛡️ ZeroTrace Stealer 13 — Advanced Client Monitoring & Data Extraction System 🔍 🛡️ ZeroTrace Stealer 13 — Advanced Client Monitoring & Data Extraction System 🔍 Latest (64-bit)
-
🚨 Zero-Day Link Exploit — Unpatched Vulnerability Access 🔓 🚨 Zero-Day Link Exploit — Unpatched Vulnerability Access 🔓 Latest (64-bit)