A vulnerability, which was classified as problematic, was found in Smash Balloon Social Post Feed Plugin up to 4.9.0 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. Such manipulation of the argument ID leads to cross site scripting.

This vulnerability is documented as CVE-2026-16775. The attack can be executed remotely. There is not any exploit available.