Unauthorized Data Modification in Social Images Widget for WordPress by Plugin Vendor
CVE-2025-13386
5.3MEDIUM
What is CVE-2025-13386?
The Social Images Widget plugin for WordPress suffers from an authorization bypass flaw, allowing unauthorized modification of data due to a missing capability check in the 'options_update' function. This vulnerability affects all versions up to and including 2.1, enabling unauthenticated attackers to potentially delete plugin settings by tricking a site administrator into unwittingly executing a forged request.
Affected Version(s)
Social Images Widget * <= 2.1