CyberRota Analysis
AI-GeneratedThe Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery due to inadequate nonce validation in the maybe_connection_data function, affecting all versions up to 6.11.1. This flaw allows unauthenticated attackers to potentially overwrite Instagram and Facebook oEmbed access tokens by tricking site administrators into executing malicious actions. WordPress site administrators using this plugin should prioritize applying updates to mitigate the risk of unauthorized access and token manipulation.
Original NVD Description
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.