LIQUID SPEECH BALLOON
LIQUID SPEECH BALLOON has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2026; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.6, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Cross-Site Request Forgery (CSRF).
2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
3 independent researchers contributed these findings, one record each. LIQUID SPEECH BALLOON is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-65527LIQUID SPEECH BALLOON <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

LIQUID SPEECH BALLOON
Author
lqd
Create a talk style design in the block editor. Gutenberg Editor Blocks Plugin. Compatible with AMP. Settings Avatar, Name Direction: Left, Right Design: Default, Bubble, Square, Dashed, Shadow, Borderless Size: Default, Small, Large Options: Default, Short, Vertical Background color, Text color latest information on LIQUID PRESS.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C