plugin

Social Photo Feed Widget Vulnerabilities

3 known security issues reported for the Social Photo Feed Widget WordPress plugin. Most recent disclosed May 1, 2026.

1 high 2 medium

Running Social Photo Feed Widget on your site? Check whether your installed version is affected.

Scan your site free

Widgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpoints

medium

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and includin...

CVSS:
6.5
Affected:
up to 1.8
Fixed in:
1.8.1
Disclosed:
May 1, 2026

CVE-2025-14726 on NVD →

Widgets for Social Photo Feed <= 1.7.9 - Unauthenticated Stored Cross-Site Scripting via feed_data

high

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...

CVSS:
7.2
Affected:
up to 1.7.9
Fixed in:
1.8.0
Disclosed:
Apr 3, 2026

CVE-2026-5425 on NVD →

Widgets for Social Photo Feed <= 1.7.8 - Missing Authorization

medium

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
Dec 23, 2025

CVE-2025-68595 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database