CVE-2025-14726
MEDIUM NUCLEIWidgets for Social Photo Feed < 1.8 - Sensitive Data Exposure & Modification via REST API
Title source: llmExploitation Summary
CVE-2025-14726 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to access and update plugin settings.
Nuclei Templates (1)
WordPress Widgets for Social Photo Feed <= 1.8 - Information Disclosure
MEDIUMVERIFIEDby 0x_Akoko
FOFA:
body="/wp-content/plugins/social-photo-feed-widget/"
Scores
CVSS v3
6.5
EPSS
0.0386
EPSS Percentile
88.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
trustindex/Widgets for Social Photo Feed
< 1.8
Published
May 02, 2026
Tracked Since
May 02, 2026