What the vulnerability does
01Description
Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.
Explanation of Vulnerability in Simple Terms
Sticky Social Media Icons version 2.1 and earlier lacks proper authorization checks, allowing authenticated users with low privileges to modify or disable site functionality. An attacker with a basic user account can alter plugin settings without proper permission validation. This affects the integrity and availability of the social media icon feature on affected WordPress sites.
What an attacker can do
Modify or disable the plugin's social media icon settings with a low-privilege user account.
Potential impact on your site
Unauthorized users can alter your social media icon configuration, potentially disrupting site branding or removing social links.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the WordPress site; no user interaction required.
Key dates
External resources
Related vulnerabilities