PT-2025-51811 · WordPress · Wp Social Ninja

Angus Girvan

·

Published

2025-12-17

·

Updated

2025-12-17

·

CVE-2025-13880

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) versions prior to 4.0.2
Description The WP Social Ninja plugin for WordPress is susceptible to unauthorized access and modification of data. This is due to a missing capability check within the getAdvanceSettings and saveAdvanceSettings functions. An unauthenticated attacker can view and modify the plugin’s advanced settings.
Recommendations Update to version 4.0.2 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13880

Affected Products

Wp Social Ninja