CVE-2025-14726
Last modified
CVE-2025-14726 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to access and update plugin settings.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to access and update plugin settings.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-14726?
How severe is CVE-2025-14726?
How do I fix CVE-2025-14726?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-14719The Relevanssi WordPress plugin before 4.26.0, Relevanssi P…4.9
- CVE-2025-1472Mattermost versions 9.11.x <= 9.11.8 fail to properly perfor…4.3
- CVE-2025-14720The Booking for Appointments and Events Calendar – Amelia pl…5.3
- CVE-2025-14721The Responsive and Swipe slider plugin for WordPress is vuln…5.5
- CVE-2025-14722A vulnerability was determined in vion707 DMadmin up to 3403…2.4
- CVE-2025-14725The Internal Link Builder plugin for WordPress is vulnerable…4.4
- CVE-2025-14727A vulnerability exists in NGINX Ingress Controller's nginx.o…8.7
- CVE-2025-14728Rapid7 Velociraptor versions before 0.75.6 contain a directo…6.8
- CVE-2025-14729A vulnerability was identified in CTCMS Content Management S…7.2
- CVE-2025-1473A Cross-Site Request Forgery (CSRF) vulnerability exists in …7.1
- CVE-2025-14730A security flaw has been discovered in CTCMS Content Managem…7.2
- CVE-2025-14731A weakness has been identified in CTCMS Content Management S…7.2
Are you affected by CVE-2025-14726?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
