CVE-2025-26758: WordPress Spotlight Social Feeds plugin <= 1.7.1 - Sensitive Data Exposure vulnerability

Medium (5.3)

Sign up for FREE to recieve instant alerts about this vulnerability!

Description

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social Media Feeds allows Retrieve Embedded Sensitive Data. This issue affects Spotlight Social Media Feeds: from n/a through 1.7.1.

Classification

CVE ID: CVE-2025-26758

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

Vendor: RebelCode

Product: Spotlight Social Media Feeds

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 0.11988 (how common is this exploit)

EPSS Date: 2025-03-15 (when was this score calculated)

Timeline