6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the getAdvanceSettings and saveAdvanceSettings functions in all versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to view and modify plugin's advanced settings.
Basic Information
ID
CVE-2025-13880
Source
Wordfence
Published
Dec 17, 2025 at 04:31
Affected Product
Vendor
adreastrian
Product
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets
Version
*
Affected Versions
adreastrian WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/8b8e3cb9-00b3-4500-adf0-c8a9fbf9d546
- plugins.trac.wordpress.org /browser/wp-social-reviews/tags/4.0.1/app/Http/Routes/api.php
- plugins.trac.wordpress.org /browser/wp-social-reviews/tags/4.0.1/app/Http/Policies/SettingsPolicy.php
- plugins.trac.wordpress.org /browser/wp-social-reviews/tags/4.0.1/app/Services/PermissionManager.php
- plugins.trac.wordpress.org /browser/wp-social-reviews/tags/4.0.1/app/Http/Controllers/SettingsController.php