What is CVE-2026-15452?
The Smash Balloon Social Photo Feed plugin for WordPress up to version 6.11.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via the REQUEST_URI Query String due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to execute arbitrary scripts in a user's browser. Updating to the latest version is recommended.
Azərbaycanca: Smash Balloon Social Photo Feed plaqininin 6.11.3-ə qədər olan versiyalarında REQUEST_URI Query String vasitəsilə Reflected Cross-Site Scripting (XSS) zəifliyi aşkar edilib. Bu zəiflik autentifikasiya olunmamış hücumçulara, kifayət qədər input sanitization və output escaping olmadığı üçün, istifadəçi brauzerində ixtiyari skript işlətməyə imkan verir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Smash Balloon
FAQ2
What is the CVE-2026-15452 vulnerability in the Smash Balloon Social Photo Feed plugin?
It is a Reflected Cross-Site Scripting (XSS) vulnerability present in versions up to 6.11.3 of the plugin. The vulnerability occurs via the REQUEST_URI Query String and allows unauthenticated attackers to execute arbitrary scripts in a user's browser.
How to protect against CVE-2026-15452?
It is recommended to update the Smash Balloon Social Photo Feed plugin to the latest version, as the vulnerability was discovered in versions up to 6.11.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.