5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4.9.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate Instagram profile and media data from any account the site owner connected to their site.
Basic Information
ID
CVE-2025-10637
Source
Wordfence
Published
Oct 25, 2025 at 06:49
Affected Product
Vendor
quadlayers
Product
Social Feed Gallery
Version
*
Affected Versions
quadlayers Social Feed Gallery *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/ae0dd6b0-9028-456e-9843-d45754c01c53
- wordpress.org /plugins/insta-gallery/
- plugins.trac.wordpress.org /browser/insta-gallery/tags/4.9.2/lib/api/rest/endpoints/frontend/class-user-profile.php
- plugins.trac.wordpress.org /changeset/3381423/insta-gallery/trunk/lib/api/rest/endpoints/frontend/class-user-profile.php