Description
WordPress Plugin 10Web Social Feed for Instagram is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin settings. WordPress Plugin 10Web Social Feed for Instagram version 1.3.18 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
PHP NULL Pointer Dereference Vulnerability (CVE-2017-6441)
WordPress 5.4.x Multiple Vulnerabilities (5.4 - 5.4.11)
WordPress 5.4.x Multiple Vulnerabilities (5.4 - 5.4.4)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7834)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2018-14720)