What the vulnerability does
01Description
Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.
Explanation of Vulnerability in Simple Terms
The Social Icons Widget & Block by WPZOOM plugin for WordPress does not properly check user permissions before allowing modifications to widget settings. A logged-in user with low privileges can alter widget configuration, including social media links and display options, without authorization. This affects versions up to 4.2.15.
What an attacker can do
Modify social media widget settings and links without proper authorization.
Potential impact on your site
Unauthorized users can change social media links, potentially redirecting visitors to malicious sites or defacing your social presence.
Conditions required to exploit
Attacker must be logged in to WordPress with at least low-level user privileges.
Key dates
External resources
Related vulnerabilities