Description
WordPress Plugin 10Web Social Feed for Instagram is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin settings. WordPress Plugin 10Web Social Feed for Instagram version 1.3.18 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin WBW Currency Switcher for WooCommerce Cross-Site Scripting (1.6.5)
Jetty Uncontrolled Resource Consumption Vulnerability (CVE-2020-27223)
PHP Other Vulnerability (CVE-2015-6838)
MySQL Other Vulnerability (CVE-2010-3680)
WordPress Plugin Disable Image Right Click Cross-Site Scripting (1.0)