Widgets for Social Photo Feed WordPress plugin <= 1.8 contains a broken access control caused by missing capability checks on specific REST API endpoints, letting unauthenticated attackers access and modify plugin settings remotely.
id: CVE-2025-14726
info:
name: WordPress Widgets for Social Photo Feed <= 1.8 - Information Discl
...