Description
Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) allows Retrieve Embedded Sensitive Data.This issue affects Spotlight - Social Media Feeds (Premium): from n/a through 1.7.1.
Published: 2025-05-26
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves the insertion of sensitive information into data sent by the WordPress Spotlight - Social Media Feeds (Premium) plugin, allowing an attacker to retrieve embedded sensitive data. This flaw corresponds to CWE‑201, which addresses the exposure of sensitive information through application output. The effect is that confidential information can be accessed by unauthorized parties, compromising data confidentiality and potentially enabling further exploitation if the exposed data is used in other attacks.

Affected Systems

The affected product is the Spotlight – Social Media Feeds (Premium) WordPress plugin for all versions up to 1.7.1. No other versions or products are listed as impacted, and no vendor‑supplied version details are available beyond the general affected range.

Risk and Exploitability

According to the CVSS score of 5.3, the vulnerability carries a medium severity rating. The EPSS score of less than 1% indicates a very low probability that it will be actively exploited in the wild at present. The vulnerability is not included in the CISA KEV catalog. An attacker would likely need to obtain access to a site using the vulnerable plugin and trigger its feed generation functionality, then intercept the output to extract the sensitive data; no remote code execution or elevated privileges are required. The lack of a listed exploit reduces the urgency, but data exposure remains a security concern.

Generated by OpenCVE AI on April 30, 2026 at 18:46 UTC.

Remediation

Vendor Solution

Update the WordPress Spotlight - Social Media Feeds (Premium) wordpress plugin to the latest available version (at least 1.7.2).


OpenCVE Recommended Actions

  • Update to plugin version 1.7.2 or later
  • Disable or remove the plugin if it is not required for the site's functionality
  • Audit recent plugin output and server logs to identify any instances of exposed sensitive data, and clear any remnants.

Generated by OpenCVE AI on April 30, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-27963 Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) allows Retrieve Embedded Sensitive Data.This issue affects Spotlight - Social Media Feeds (Premium): from n/a through 1.7.1.
History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) spotlight-social-photo-feeds-premium allows Retrieve Embedded Sensitive Data.This issue affects Spotlight - Social Media Feeds (Premium): from n/a through <= 1.7.1. Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) allows Retrieve Embedded Sensitive Data.This issue affects Spotlight - Social Media Feeds (Premium): from n/a through 1.7.1.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) allows Retrieve Embedded Sensitive Data.This issue affects Spotlight - Social Media Feeds (Premium): from n/a through 1.7.1. Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) spotlight-social-photo-feeds-premium allows Retrieve Embedded Sensitive Data.This issue affects Spotlight - Social Media Feeds (Premium): from n/a through <= 1.7.1.
References

Tue, 27 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 May 2025 14:15:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) allows Retrieve Embedded Sensitive Data.This issue affects Spotlight - Social Media Feeds (Premium): from n/a through 1.7.1.
Title WordPress Spotlight - Social Media Feeds (Premium) plugin <= 1.7.1 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:32.978Z

Reserved: 2025-04-16T06:24:15.128Z

Link: CVE-2025-39498

cve-icon Vulnrichment

Updated: 2025-05-27T14:13:00.385Z

cve-icon NVD

Status : Deferred

Published: 2025-05-26T14:15:19.657

Modified: 2026-04-28T19:32:01.773

Link: CVE-2025-39498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T19:00:14Z

Weaknesses