PT-2026-36567 · WordPress · My Social Feeds
Teerachai Somprasong
·
Published
2026-05-02
·
Updated
2026-05-02
·
CVE-2026-6446
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
My Social Feeds – Social Feeds Embedder versions prior to 1.0.5
Description
The plugin is subject to sensitive information exposure via the 'ttp get accounts' AJAX action. The
get accounts() function lacks authorization checks and nonce verification, allowing authenticated attackers with Subscriber-level access or higher to retrieve the full contents of the ttp tiktok accounts WordPress option. This includes sensitive TikTok OAuth credentials, specifically access token and refresh token values from administrator-connected accounts, which can be used to impersonate the site owner when interacting with the TikTok API.Recommendations
Update the plugin to a version later than 1.0.4.
As a temporary workaround, restrict access to the 'ttp get accounts' AJAX action to prevent unauthorized users from calling the
get accounts() function.Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
My Social Feeds