PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14726 trustindex CVE debrief

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This vulnerability allows unauthenticated attackers to access and update plugin settings, potentially leading to unauthorized access and data modification. Defenders should assess potential exposure and impact, focusing on verifying exposure, assessing potential impact, and updating the plugin.

Vendor
trustindex
Product
Widgets for Social Photo Feed
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-02
Original CVE updated
2026-09-30
Advisory published
2026-05-02
Advisory updated
2026-09-30

Who should care

Defenders responsible for WordPress installations using the Widgets for Social Photo Feed plugin should assess potential exposure and impact. This includes verifying exposure, assessing potential impact, and updating the plugin to a version that addresses the vulnerability. Additionally, defenders should review compensating controls for exposed systems and check relevant monitoring, detection, and logs for exposed assets.

Why it matters

The vulnerability in the Widgets for Social Photo Feed plugin for WordPress allows unauthenticated attackers to access and update plugin settings, potentially leading to unauthorized access and data modification. Defenders should prioritize verifying exposure, assessing potential impact, and updating the plugin.

  • Potential unauthorized access to plugin settings
  • Possible modification of plugin data by unauthenticated attackers
  • Need for verification of exposure and potential impact
  • Priority on updating the plugin to address the vulnerability

Technical summary

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to access and update plugin settings, potentially leading to unauthorized access and data modification. The vulnerability's technical details are based on the CVE Program record and NVD entry.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, focusing on systems using the affected plugin versions.

Recommended defensive actions

  • Verify if systems using the Widgets for Social Photo Feed plugin are exposed to the vulnerability
  • Assess potential impact of unauthorized access and data modification
  • Consider updating the plugin to a version that addresses the vulnerability
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and severity. However, additional information on potential exploitation or affected systems is limited. Defenders should verify exposure and assess potential impact, focusing on systems using the affected plugin versions. The vulnerability's details are based on the CVE Program record and NVD entry, which provide source-provided CVE metadata and official vulnerability assessment.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-14726 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-14726

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-14726 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14726

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.