CVE-2025-10637 MEDIUM

CVE-2025-10637: Social Feed Gallery <= 4.9.2 - Missing Authorization to Unauthenticated Information Exposure

Vendor Quadlayers
Product Social Feed Gallery
Weakness CWE-862 · Missing authorization
Published October 25, 2025
Last update April 8, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4.9.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate Instagram profile and media data from any account the site owner connected to their site.

Explanation of Vulnerability in Simple Terms

02Summary

Social Feed Gallery through version 4.9.2 fails to properly check user permissions before allowing access to certain data. An unauthenticated attacker can read sensitive information without needing to log in or interact with the site. The vulnerability affects all versions from release through 4.9.2.

What an attacker can do

03Attacker Capabilities

Read sensitive data without authentication or user interaction.

Potential impact on your site

04Site Impact

Unauthorized visitors can access data that should be restricted, potentially exposing private information.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user action required.

Key dates

06Disclosure timeline

October 25, 2025 CVE published
April 8, 2026 Record updated