Description
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to access and update plugin settings.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version
Timeline
| 2025-12-15: | Vendor Notified |
| 2026-05-01: | Disclosed |
Credits
German
References
www.wordfence.com/...-4072-435a-8a1c-ca6fd964a260?source=cve
plugins.trac.wordpress.org/...13612/social-photo-feed-widget