The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 91,298 live websites that are affected by CVE-2026-16775.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 91,298 live websites (100% of Smash Balloon Social Post Feed install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 108 versions ( 100% of all versions) |
| 27,795 websites | |
| 7,720 websites | |
| 6,543 websites | |
| 5,791 websites | |
| 4,523 websites | |
| 3,865 websites | |
| 3,626 websites | |
| 2,456 websites | |
| 2,355 websites | |
| 2,316 websites |
| .com | 32,741 websites |
| .org | 8,375 websites |
| .de | 4,664 websites |
| .co.uk | 4,093 websites |
| .nl | 3,665 websites |
| .fr | 2,868 websites |
| .it | 2,667 websites |
| .se | 2,286 websites |
| .com.au | 2,028 websites |
| .fi | 1,895 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.*********.com | *,*** | ||
| *******************.com | **,*** | ||
| ****************.ro | **,*** | ||
| **************.com | **,*** | ||
| ************.com | **,*** | ||
| ***************.org | **,*** | ||
| ***********.eu | **,*** | ||
| ******.**.**.uk | **,*** | ||
| *******.com | **,*** | ||
| ***.de | **,*** |
FAQ