SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12002

MEDIUM · CVSS 4.7 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery due to inadequate nonce validation in the maybe_connection_data function, affecting all versions up to 6.11.1. This flaw allows unauthenticated attackers to potentially overwrite Instagram and Facebook oEmbed access tokens by tricking site administrators into executing malicious actions. WordPress site administrators using this plugin should prioritize applying updates to mitigate the risk of unauthorized access and token manipulation.

CVE
CVE-2026-12002
Severity
MEDIUM
CVSS
4.7
EPSS
0.10%
WordPress

Original NVD Description

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers to overwrite the site's Instagram and Facebook oEmbed access tokens via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.