My Social Feeds – bring your social content into WordPress
My Social Feeds – bring your social content into WordPress has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.
The most common weakness is Insufficiently Protected Credentials, behind 1 of the records (100%).
The one issue recorded for My Social Feeds – bring your social content into WordPress has a vendor fix available, so running the current release closes it.
All of these findings were reported by Teerachai Somprasong. My Social Feeds – bring your social content into WordPress is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.3.
CVE-2026-6446My Social Feeds <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'ttp_get_accounts' AJAX Action
Read the full analysisVulnerability Records

My Social Feeds – bring your social content into WordPress
Author
bPlugins
Show your latest Instagram posts, TikTok videos, Pinterest pins, and Twitter timeline right on your website – and keep it fresh automatically. Demos | Pricing | Documentation Why My Social Feeds? My Social Feeds is a powerful Gutenberg block plugin that lets you embed social media feeds on your WordPress website. Display Instagram posts, TikTok videos, Pinterest pins, and Twitter timelines with full control over layout, design, and behavior – columns, gaps, colors, profiles, buttons, popups, and more. Setup is simple: add your social access token where required, customize the layout from the block sidebar, and you’re ready to go. Each network gets its own dedicated block, so you can mix and match feeds anywhere the block editor works. Free Features Instagram Feed: Layout Control: Columns, row gap, and column gap settings, plus number of displayed items. Profile Options: Show/hide profile with adjustable profile image size. Interactive Elements: Show/hide Load More, Caption, and Follow buttons; open gallery item links in a new tab. Styling: Background color, border, and padding settings. Image Effects: Rotate in, rotate out, shine, zoom in, zoom out. Performance: Cache time configuration. TikTok Feed: Easy Authorization: Authorize, remove authorization, and clear cache in a click. Profile Display: Show/hide profile image, name, share button, info count, and biography, with alignment, color, background, and padding controls. Video Layout: Column control, column/row gaps, and device-based feed-per-page settings. Video Popup: Lightbox with slider and thumbnails; loads 9 videos by default with a styled Load More button. Pinterest Pins: Flexible Display: Show/hide profile, pins, image, name, about, follower count, pin count, and Follow button. Aspect Ratios: 16:9, 4:3, 1:1, 3:4, and portrait 9:16. Responsive Layout: Adjustable columns with slider or manual input, plus column and row gap control. Lightbox: Enable/disable with controls for Info Bar, Zoom In/Out, Slide Show, Thumbs, and Close. Full Styling: Profile background, image overlay, typography, colors, hover colors, padding, and borders. Twitter: Timeline Embed: Add a Twitter timeline with height, width, scrolling, and theme options. Buttons: Add Follow and Tweet buttons with color, background, font size, and padding styling. Pro Version – More Layouts & Deeper Control Upgrade to My Social Feeds Pro for advanced layouts and fine-grained customization. Pro features include: Instagram: Popup modal feed details, name and biography in the profile area, footer Follow button, hashtag removal from captions, and full color control. TikTok: Default, Slider, and Masonry layouts, videos-per-page control, overlay like/share/view counts, “View on TikTok” button, cache time control, and complete typography and color settings. Pinterest: Default, Masonry, Slider, and Justified layouts, image ratio control, extra lightbox controls (Toggle 1:1, Rotate, Flip), and typography for every element. Twitter: Hide timeline header/footer, timeline language translation, latest Twitter icon support, custom Tweet button text, hashtag support, and embedding of specific tweets and tweet videos. How to Use Install and activate the My Social Feeds plugin. Add the My Social Feeds block from the “Widgets” category in Gutenberg. Connect your feed (add an access token where required). Customize settings from the right sidebar. Publish – your social feed is live! Use Cases Creators & Influencers: Showcase your latest TikTok videos and Instagram posts on your own site. Brands & Shops: Build social proof with live feeds and Follow buttons. Bloggers: Keep pages fresh with your Twitter timeline and Pinterest boards. Agencies: Embed client social content with layout and branding control. Did you like this plugin or have suggestions? Send feedback Check Out Our Plugins 🔥 b Blocks – https://bblockswp.com 🔥 HTML5 Audio Player – https://bplugins.com/products/html5-audio-player 🔥 HTML5 Video Player – https://bplugins.com/products/html5-video-player 🔥 PDF Poster – https://bplugins.com/products/pdf-poster 🔥 StreamCast – https://bplugins.com/products/streamcast-radio-player 🔥 3D Viewer – https://bplugins.com/products/3d-viewer Source Code You can find the source code, report bugs, and contribute to the development of this plugin on our GitHub repository: My Social Feeds on GitHub Third-party Libraries @fancyapps/ui (Fancybox & Carousel) Used for: Lightbox popup, carousel slider, and thumbnail navigation Version: 5.0.36 Source: https://fancyapps.com/ License: Fancyapps UI License License URI: https://fancyapps.com/pricing/ bpl-tools Source / GitHub: https://github.com/bPlugins/bpl-tools License: GPL-2.0-or-later – https://www.gnu.org/licenses/gpl-2.0.html Purpose: Shared utility library providing admin dashboard components and common Gutenberg editor controls. External Services: The library may connect to bPlugins, WordPress.org, and Freemius services for product data and checkout functionality. See full details: https://github.com/bPlugins/bpl-tools#external-requests–why-they-are-made Freemius Lite SDK Source: https://bplugins.com/ GitHub: https://github.com/bPlugins/freemius-lite-sdk License: GPL-2.0-or-later – https://www.gnu.org/licenses/gpl-2.0.html Purpose: Provides an opt-in consent form for usage tracking and analytics to help improve the plugin. No data is sent before explicit user consent. External Services: Communicates with api.bplugins.com (activation events) and wp.freemius.com (opt-in processing) only after user opt-in. See bPlugins Privacy Policy and Freemius Privacy Policy.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C