CVE-2025-14726

MEDIUM NUCLEI

Widgets for Social Photo Feed < 1.8 - Sensitive Data Exposure & Modification via REST API

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-14726 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to access and update plugin settings.

Nuclei Templates (1)

WordPress Widgets for Social Photo Feed <= 1.8 - Information Disclosure
MEDIUMVERIFIEDby 0x_Akoko
FOFA: body="/wp-content/plugins/social-photo-feed-widget/"

Scores

CVSS v3 6.5
EPSS 0.0386
EPSS Percentile 88.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
trustindex/Widgets for Social Photo Feed < 1.8
Published May 02, 2026
Tracked Since May 02, 2026