Sceawere
Vulnerability Detail
CVE-2026-39787UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Broken Access Control Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 16h ago
- Vendor
- 10Web
- Product
- 10Web Social Photo Feed
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-06T09:17:51.267Z",
"pubdate": "2026-10-06T09:17:51.267Z",
"executiveSummary": "The 10Web Social Photo Feed plugin, in versions 1.4.35 and earlier, is susceptible to an unauthenticated broken access control vulnerability.\nThis vulnerability exists due to insufficient authorization checks within the plugin's request handling mechanism, allowing unauthenticated attackers to perform unauthorized actions or access restricted data.\nThe flaw poses a significant security risk as it bypasses standard WordPress permission models, enabling an attacker to interact with plugin functionality without requiring administrative or even subscriber-level privileges.\nThe scope of impact depends on the specific actions exposed by the affected endpoints, which could range from unauthorized configuration changes to the retrieval of sensitive system or feed data.\nExploitation requires no specialized credentials, making this a high-priority risk for installations where external access to the WordPress API or plugin-specific endpoints is exposed to the public internet.\nImmediate remediation is necessary to ensure the integrity and confidentiality of the affected WordPress environment.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of access control checks within the plugin's request handling logic. In WordPress development, functions tasked with processing AJAX requests or REST API endpoints must strictly validate user capabilities using functions such as current_user_can(). In the case of 10Web Social Photo Feed <= 1.4.35, the code fails to verify the authorization level of the requesting user before executing core plugin functionalities.\nThe vulnerability manifests when the plugin exposes handler functions that perform sensitive operations but neglect to check for valid nonces or user authorization levels. Because the vulnerable code paths do not enforce these checks, an unauthenticated remote attacker can craft specific HTTP requests—typically via GET or POST methods targeting admin-ajax.php or similar plugin-registered entry points—to invoke these functions.\nThe attack flow proceeds as follows: First, the attacker identifies the endpoint associated with the 10Web Social Photo Feed plugin. Second, the attacker determines the specific parameters required to trigger the desired action. Because there is no server-side enforcement of authorization, the plugin processes the request as if it were initiated by a legitimate, authorized administrator.\nThe lack of authentication requirements means that any remote user can trigger these backend functions. This exposure allows for the unauthorized retrieval of data, modification of plugin settings, or potentially the execution of higher-level administrative tasks if the underlying functions do not validate the state of the application correctly.\nThe impact of this exploit is severe, as it grants attackers a degree of control over the plugin’s features that should be strictly reserved for privileged users. If the plugin configuration contains sensitive tokens or access data for third-party platforms (like Instagram or Facebook), these could be exfiltrated. Furthermore, modifying settings can facilitate further exploitation vectors, such as redirecting feeds or tampering with display content, potentially leading to cross-site scripting (XSS) or other content-injection attacks depending on how the plugin renders the user-supplied data."
}