What is CVE-2026-16775?
A Stored Cross-Site Scripting vulnerability via the 'id' Shortcode Attribute has been found in the Smash Balloon Social Post Feed plugin up to version 4.9.0. This allows an authenticated attacker to execute arbitrary code in users' browsers. Users are advised to immediately update the plugin to the latest version.
Azərbaycanca: Smash Balloon Social Post Feed plaqininin 4.9.0 versiyasına qədər olan bütün versiyalarında 'id' shortcode atributu vasitəsilə Stored Cross-Site Scripting zəifliyi aşkar edilib. Bu, autentifikasiya olunmuş hücumçuya istifadəçilərin brauzərində ixtiyari kod icra etməyə imkan yaradır. İstifadəçilərə dərhal plaqini ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Smash Balloon
FAQ2
What vulnerability affects the Smash Balloon Social Post Feed plugin?
A Stored Cross-Site Scripting vulnerability via the 'id' Shortcode Attribute affects the plugin in versions up to 4.9.0.
What should users do to protect against this vulnerability?
Users are advised to immediately update the plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.