Medium 4.3
2025-10-22< 4.3.3
CVE-2025-49937
Minimum safe version
4.3.3
Update to 4.3.3 or later to address 8 fixable vulnerabilities
CVE-2025-49937
WordPress Smash Balloon Social Post Feed Plugin <= 4.3.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-31379
Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting
CVE-2022-4477
CVE-2021-24508
CVE-2021-24918
CVE-2021-25065