vulnerability
WordPress Plugin: social-photo-feed-widget: CVE-2025-14726: Exposure of Sensitive Information to an Unauthorized Actor
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:N/AC:L/Au:N/C:N/I:P/A:P) | May 1, 2026 | May 4, 2026 | May 4, 2026 |
Severity
6
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
Published
May 1, 2026
Added
May 4, 2026
Modified
May 4, 2026
Description
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to access and update plugin settings.
Solution
social-photo-feed-widget-plugin-cve-2025-14726
References
- https://www.cve.org/CVERecord?id=CVE-2025-14726
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ab15fa8b-4072-435a-8a1c-ca6fd964a260?source=api-prod
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209610
- CVE-2025-14726
- https://attackerkb.com/topics/CVE-2025-14726
- CWE-200
- EUVD-EUVD-2025-209610
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.