Sceawere

Vulnerability Detail

CVE-2026-93756UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS via Facebook Feed

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
15h ago
Vendor
smub
Product
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator accesses the feed builder preview page. This attack requires only a Facebook account to post a comment on the connected Facebook Page, with no WordPress credentials needed; additionally, the use of v-show rather than v-if means injected HTML — including onerror handlers — is evaluated in the DOM even when the comment section is not visually displayed. When combined with the lack of URL validation in the cff_install_addon AJAX handler (admin/addon-functions.php), an injected script running in an administrator's session can trigger arbitrary plugin installation from an attacker-controlled URL, which may result in server-side code execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T08:17:03.240Z",
  "pubdate": "2026-10-02T08:17:03.240Z",
  "executiveSummary": "The Smash Balloon Social Post Feed plugin for WordPress (versions up to and including 4.13.0) is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability via the Facebook Comment Message field.\nThis vulnerability allows unauthenticated remote attackers to inject malicious JavaScript into the plugin's Admin Builder Preview.\nBecause the payload is rendered in the administrator's context, the script executes automatically when an administrator visits the feed builder page.\nThe use of the Vue.js 'v-html' directive without adequate sanitization, combined with the 'v-show' directive, ensures that malicious payloads, such as 'onerror' handlers, remain resident in the Document Object Model (DOM) regardless of visual visibility.\nThe impact is critical, as the XSS can be chained with an insecure AJAX handler (cff_install_addon) to force the installation of arbitrary, potentially malicious plugins from attacker-controlled URLs, leading to full server-side code execution.\nThis attack requires no WordPress authentication and leverages the public-facing nature of connected Facebook Pages to deliver the payload.",
  "technicalDetails": "The root cause of the vulnerability lies in the insufficient input sanitization and improper output escaping within the plugin's Admin Builder Preview interface. The plugin retrieves data from connected Facebook feeds and renders the comment message content using the 'v-html' directive in Vue.js. Because the content is not sanitized before being bound to the DOM, malicious scripts embedded in Facebook comments are rendered as executable code.\nThe exploitation mechanism is facilitated by the plugin's choice of the 'v-show' directive. Unlike 'v-if', which conditionally adds or removes elements from the DOM, 'v-show' merely toggles the CSS display property. Consequently, even if the comment section is not explicitly displayed to the administrator, the injected malicious HTML—including event handlers such as 'onerror' or 'onload'—remains present and active within the DOM tree.\nThe attack flow begins when an unauthenticated attacker posts a comment containing a malicious payload (e.g., an '<img>' tag with an 'onerror' attribute) to a Facebook Page integrated with the vulnerable plugin. When a WordPress administrator navigates to the plugin's feed builder preview page, the plugin fetches the malicious data via the Facebook API. Upon rendering the feed in the administrative dashboard, the malicious script executes within the administrator's authenticated session.\nThe post-exploitation scenario is particularly severe due to a secondary vulnerability in the 'cff_install_addon' AJAX handler located in 'admin/addon-functions.php'. This handler lacks proper URL validation for the plugin installation process. By leveraging the initial Stored XSS, an attacker can programmatically trigger a call to the 'cff_install_addon' function. This allows the attacker to specify an external, malicious URL from which the server will attempt to download and install a plugin. By hosting a backdoored plugin at the controlled URL, the attacker achieves remote code execution (RCE) on the underlying web server, effectively gaining full control over the WordPress environment.\nThis multi-stage chain demonstrates a critical risk where an unauthenticated entry point (Facebook comment) leads to administrative session compromise, which is subsequently leveraged to bypass security controls in administrative AJAX functions, ultimately resulting in a full system takeover."
}
CVE-2026-93756: Stored XSS via Facebook Feed (HIGH Severity, CVSS: 7.2) | Sceawere