Skip to content

Known CVE

WordPress Widgets for Social Photo Feed <= 1.8 - Information Disclosure

Widgets for Social Photo Feed WordPress plugin <= 1.8 contains a broken access control caused by missing capability checks on specific REST API endpoints, letting unauthenticated attackers access and modify plugin settings remotely.

CVE-2025-14726

Medium2025CVSS 6.5CWE-200CWE-862

cve2025 · wp · wordpress · wp-plugin · social-photo-feed-widget · disclosure

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website