Executive brief
WP Social Ninja is a WordPress plugin used to integrate social media feeds and reviews into websites. A security vulnerability in versions 4.3.0 and earlier allows unauthenticated visitors to access sensitive system information that should be restricted. This exposure could provide attackers with technical details useful for planning more advanced attacks against the website.
Technical details
The WP Social Ninja plugin for WordPress is vulnerable to sensitive data exposure (CWE-497) in versions up to and including 4.3.0. The vulnerability allows an unauthenticated remote attacker to access sensitive system information due to insufficient access controls on certain plugin components or endpoints. This data exposure can be leveraged by an attacker to gather intelligence for further exploitation. The issue is resolved in version 4.3.1.
Affected products
- Mahmudul Hasan Arif WP Social Ninja <= 4.3.0
Timeline
- 2026-07-16: other: Reported by researcher Ananda Dhakal
- 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD
- 2026-07-23: patched: Patch released in version 4.3.1