CVE-2024-49685: Smashballoon Custom Twitter Feeds

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets Widget): from n/a through <= 2.2.3.

Affected products

  • Smashballoon Custom Twitter Feeds: before 2.2.4 (fixed in 2.2.4)

Published 2024-10-31. Last modified 2026-06-17.