CVE · Medium

CVE-2025-10637 — Social Feed Gallery [insta-gallery] < 4.9.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-10637 Social Feed Gallery [insta-gallery] < 4.9.3 Missing Authorization Medium 5.3 < 4.9.3 4.9.3 2025-10-24

CVE-2025-10637

The Social Feed Gallery WordPress plugin has a security flaw in versions up to 4.9.2, allowing unauthorized access to sensitive information. Specifically, an attacker can exploit this vulnerability to extract Instagram profile details and associated media content without needing authentication. This issue arises from inadequate checks on user permissions within the plugin's code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.