
CVE-2026-5425 The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and includ… https://www.cve.org/CVERecord?id=CVE-2026-5425
Post summary
The post announces CVE-2026-5425, a stored XSS vulnerability in the Widgets for Social Photo Feed WordPress plugin, without mention of exploitation, PoC, or mitigation.

