A vulnerability, which was classified as problematic, was found in trustindex Widgets for Social Photo Feed Plugin up to 1.7.9 on WordPress. This affects an unknown function. The manipulation of the argument feed_data results in cross site scripting. This vulnerability was named CVE-2026-5425. The attack may be performed from remote. There is no available exploit. You should upgrade the affected component.
| Vendor | Product | Versions |
|---|---|---|
| trustindex | widgets for social photo feed | 0 |
Updated description with additional details and clarified that there is no available exploit and it is not actively exploited.
Initial creation