Description
WordPress Plugin Smash Balloon Social Post Feed is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugin's settings. WordPress Plugin Smash Balloon Social Post Feed version 4.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0.1 or latest
References
https://jetpack.com/2021/10/29/security-issues-patched-in-smash-balloon-social-post-feed-plugin/
https://plugins.svn.wordpress.org/custom-facebook-feed/trunk/README.txt
Related Vulnerabilities
Jetty Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-26048)
Atlassian Confluence CVE-2023-22515 Vulnerability (CVE-2023-22515)
Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2023-1108)
Apache Tomcat Off-by-one Error Vulnerability (CVE-2023-28709)