PatchSiren cyber security CVE debrief
CVE-2025-14726 trustindex CVE debrief
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This vulnerability allows unauthenticated attackers to access and update plugin settings, potentially leading to unauthorized access and data modification. Defenders should assess potential exposure and impact, focusing on verifying exposure, assessing potential impact, and updating the plugin.
- Vendor
- trustindex
- Product
- Widgets for Social Photo Feed
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-02
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-05-02
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for WordPress installations using the Widgets for Social Photo Feed plugin should assess potential exposure and impact. This includes verifying exposure, assessing potential impact, and updating the plugin to a version that addresses the vulnerability. Additionally, defenders should review compensating controls for exposed systems and check relevant monitoring, detection, and logs for exposed assets.
Why it matters
The vulnerability in the Widgets for Social Photo Feed plugin for WordPress allows unauthenticated attackers to access and update plugin settings, potentially leading to unauthorized access and data modification. Defenders should prioritize verifying exposure, assessing potential impact, and updating the plugin.
- Potential unauthorized access to plugin settings
- Possible modification of plugin data by unauthenticated attackers
- Need for verification of exposure and potential impact
- Priority on updating the plugin to address the vulnerability
Technical summary
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to access and update plugin settings, potentially leading to unauthorized access and data modification. The vulnerability's technical details are based on the CVE Program record and NVD entry.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, focusing on systems using the affected plugin versions.
Recommended defensive actions
- Verify if systems using the Widgets for Social Photo Feed plugin are exposed to the vulnerability
- Assess potential impact of unauthorized access and data modification
- Consider updating the plugin to a version that addresses the vulnerability
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and severity. However, additional information on potential exploitation or affected systems is limited. Defenders should verify exposure and assess potential impact, focusing on systems using the affected plugin versions. The vulnerability's details are based on the CVE Program record and NVD entry, which provide source-provided CVE metadata and official vulnerability assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14726 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14726
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14726 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14726
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3513612/social-photo-feed-widget
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.