
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68595 is a Missing Authorization vulnerability in the Trustindex "Widgets for Social Photo Feed" WordPress plugin (slug: social-photo-feed-widget) that allows low-privileged authenticated attackers to exploit incorrectly configured access control security levels. The vulnerability affects all versions of the plugin up to and including 1.8 (NVD) / 1.7.7 (ENISA/Patchstack). It was published on December 24, 2025, and assigned by Patchstack. The CVSS v3.1 base score is 8.8 (High) (Red Hat CVE, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before executing sensitive operations. The attack vector is network-based with low attack complexity, requiring only a low-privileged account (e.g., a subscriber or contributor role on a WordPress site) and no user interaction. This class of vulnerability typically manifests as unprotected AJAX handlers or REST API endpoints within the plugin that perform privileged actions without capability checks, allowing any authenticated user to trigger them (Red Hat CVE, Patchstack).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress installation. A low-privileged attacker could gain unauthorized access to sensitive plugin configuration data, modify or delete critical settings, and potentially disrupt the availability of the social photo feed functionality. Depending on the specific unprotected actions exposed, the vulnerability could also serve as a stepping stone for further compromise of the WordPress site (Red Hat CVE).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation reported for CVE-2025-68595. The EPSS score is approximately 0.039% (very low probability of exploitation in the near term). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been made at this time (Red Hat CVE, Patchstack).
social-photo-feed-widget) version 1.7.7 or earlier using tools like WPScan or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/social-photo-feed-widget/readme.txt.wp-admin/admin-ajax.php with plugin-specific action parameters from low-privileged user accounts at unusual times or frequencies.social_photo_feed or similar) in the wp_options table.WordPress site administrators should immediately update the "Widgets for Social Photo Feed" plugin to a version above 1.7.7 (or above 1.8 per NVD), as a patch has been released by Trustindex. If an immediate update is not possible, consider deactivating the plugin until it can be patched. Additionally, restrict user registration on the WordPress site to minimize the pool of potential low-privileged attackers, and review user roles to enforce the principle of least privilege (Red Hat CVE, Patchstack).
The vulnerability received limited but standard coverage from automated security news aggregators and social media bots shortly after its December 24, 2025 disclosure. The Hacker Wire shared the CVE details on Mastodon and Bluesky. No notable independent researcher commentary or significant vendor statements beyond the Patchstack advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."