CVE-2025-26758

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social Media Feeds spotlight-social-photo-feeds allows Retrieve Embedded Sensitive Data.This issue affects Spotlight Social Media Feeds: from n/a through <= 1.7.1.
Configurations

No configuration.

History

23 Apr 2026, 15:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

01 Apr 2026, 17:18

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad Exposición de información confidencial del sistema a una esfera de control no autorizada en RebelCode Spotlight Social Media Feeds permite recuperar datos confidenciales integrados. Este problema afecta a los feeds de redes sociales de Spotlight: desde n/a hasta 1.7.1.
Summary (en) Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social Media Feeds allows Retrieve Embedded Sensitive Data. This issue affects Spotlight Social Media Feeds: from n/a through 1.7.1. (en) Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social Media Feeds spotlight-social-photo-feeds allows Retrieve Embedded Sensitive Data.This issue affects Spotlight Social Media Feeds: from n/a through <= 1.7.1.
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : unknown
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/spotlight-social-photo-feeds/vulnerability/wordpress-spotlight-social-feeds-plugin-1-7-1-sensitive-data-exposure-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/spotlight-social-photo-feeds/vulnerability/wordpress-spotlight-social-feeds-plugin-1-7-1-sensitive-data-exposure-vulnerability?_s_id=cve -

17 Feb 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-17 12:15

Updated : 2026-04-23 15:25


NVD link : CVE-2025-26758

Mitre link : CVE-2025-26758

CVE.ORG link : CVE-2025-26758


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere