Sensitive Data Exposure Vulnerability in RebelCode Spotlight Social Media Feeds
CVE-2025-26758

5.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
17 February 2025

Summary

The RebelCode Spotlight Social Media Feeds plugin has a vulnerability that enables unauthorized users to retrieve sensitive embedded data. This flaw is present in versions from n/a to 1.7.1, potentially exposing sensitive system information to malicious actors. Implementing appropriate security measures and keeping the plugin updated are crucial steps to protect against this issue.

Affected Version(s)

Spotlight Social Media Feeds <= 1.7.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.