Software intelligence
Important: Instagram Feed appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
7
Latest advisory
4 August 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
instagram-feed
Plugin
This catalog lists 7 known advisories affecting Instagram Feed. The most recent was published on 4 August 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query String
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 4 August 2026
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter
May trick authenticated users into performing unintended actions.
Published 8 July 2026
Smash Balloon Instagram Feed <= 6.9.0 (Free) & <= 6.8.0 (Pro) - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-plugin` Attribute
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 28 May 2025
Known Instagram Feed advisories published by month.
CVE-2026-15452 · Published 4 August 2026
Affected versions: ≤ 6.11.3
CVE-2026-12002 · Published 8 July 2026
Affected versions: ≤ 6.11.1
CVE-2025-4583 · Published 28 May 2025
Affected versions: ≤ 6.9.0
No CVE assigned · Published 20 July 2021
Affected versions: ≤ 2.9.1
No CVE assigned · Published 5 March 2019
Affected versions: < 1.12
No CVE assigned · Published 18 January 2018
Affected versions: ≤ 1.5.1
No CVE assigned · Published 19 November 2016
Affected versions: ≤ 1.4.6.2
SiteRespond Defence matches your installed Instagram Feed version against this catalog when the Defence plugin is connected to your WordPress site.