WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Smash Balloon Social Photo Feed – Easy Social Feeds Plugin

Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.

6Reported vulnerabilities
8.8Highest CVSS score
6.12.0Latest version
1,000,000+Active installs

What to do now

Update Smash Balloon Social Photo Feed – Easy Social Feeds Plugin to 6.11.4 or later. 6 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 10, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
WF-1c307340-2911-46b9-9c90-0a7ebad8a0e9 High 8.8 Before 1.12 1.12 March 5, 2019
WF-062f5bc7-9d53-4a28-b603-9901ce2175d8 Medium 6.4 1.4.6.2 and earlier 1.4.7 November 19, 2016
WF-8247c654-0082-4677-a0a6-b90a0256de81 Medium 6.1 1.5.1 and earlier 1.6 January 18, 2018
CVE-2025-4583 Medium 5.4 0.2% 0 to 6.8.0 (inclusive)
0 to 6.9.0 (inclusive)
6.9.1 May 29, 2025
CVE-2026-15452 Medium 4.7 0.2% 0 to 6.11.3 (inclusive) 6.11.4 August 5, 2026
CVE-2026-12002 Medium 4.7 0.1% 0 to 6.11.1 (inclusive) 6.11.2 July 8, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.