CVE-2026-16775

Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 91,298 live websites that are affected by CVE-2026-16775.

Run a Free Instant Scan




Affected Software

Product  Smash Balloon Social Post Feed
Category Wordpress Plugins
Vulnerable Domains91,298 live websites (100% of Smash Balloon Social Post Feed install base)
Vulnerable Versions
  • from 0 through 4.9
Vulnerable Versions Count108 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-16775
United States27,795 websites



Germany7,720 websites
GB6,543 websites
France5,791 websites
Japan4,523 websites
Netherlands3,865 websites
Italy3,626 websites
Australia2,456 websites
Sweden2,355 websites
Denmark2,316 websites

Website Distribution by TLD

Number of websites using CVE-2026-16775
.com32,741 websites
.org8,375 websites
.de4,664 websites
.co.uk4,093 websites
.nl3,665 websites
.fr2,868 websites
.it2,667 websites
.se2,286 websites
.com.au2,028 websites
.fi1,895 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16775

Top websites that are affected by CVE-2026-16775. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*********.com United States*,***
*******************.com United States**,***
****************.ro Romania**,***
**************.com United States**,***
************.com United States**,***
***************.org United States**,***
***********.eu Hungary**,***
******.**.**.uk GB**,***
*******.com United States**,***
***.de Germany**,***
See full domain list

FAQ

CVE-2026-16775 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Smash Balloon Social Post Feed
A total of 91,298 websites have been identified as vulnerable to CVE-2026-16775, based on global website indexing conducted by WebTechSurvey.
The Smash Balloon Social Post Feed is affected by the CVE-2026-16775 vulnerability.
Smash Balloon Social Post Feed versions up to and including 4.9 are vulnerable to CVE-2026-16775.