WordPress Instagram Feed Plugin <= 6.9.0 is vulnerable to Cross Site Scripting (XSS)
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
Minimum safe version
6.9.1
Update to 6.9.1 or later to address 11 fixable vulnerabilities
Smash Balloon Plugins (Various Versions) - Reflected Cross-Site Scripting
Instagram Feed <= 1.4.6.2 - Authenticated Cross-Site Scripting (XSS) & CSRF
Instagram Feed <= 1.5.1 - Cross-Site Scripting (XSS)
Instagram Feed <= 1.11.3 - Unspecified Issues
Smash Balloon Social Photo Feed <= 1.4.6.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Smash Balloon Social Photo Feed <= 1.5.1 - Reflected Cross-Site Scripting
Smash Balloon Social Photo Feed <= 1.11.3 - Cross-Site Request Forgery to Back-Up Deletion
Multiple Plugins from Smash Balloon - Reflected Cross-Site Scripting
WordPress Instagram Feed Plugin <= 1.4.6.2 - Cross Site Request Forgery
WordPress Instagram Feed plugin <=1.5.1 - Cross-Site Scripting (XSS) vulnerability