CVE-2024-30464 MEDIUM

CVE-2024-30464: WordPress Social Icons Widget & Block by WPZOOM plugin <= 4.2.15 - Broken Access Control vulnerability

Vendor Wpzoom
Product Social Icons Widget & Block by WPZOOM
Weakness CWE-862 · Missing authorization
Published June 9, 2024
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

Explanation of Vulnerability in Simple Terms

02Summary

The Social Icons Widget & Block by WPZOOM plugin for WordPress does not properly check user permissions before allowing modifications to widget settings. A logged-in user with low privileges can alter widget configuration, including social media links and display options, without authorization. This affects versions up to 4.2.15.

What an attacker can do

03Attacker Capabilities

Modify social media widget settings and links without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users can change social media links, potentially redirecting visitors to malicious sites or defacing your social presence.

Conditions required to exploit

05Prerequisites

Attacker must be logged in to WordPress with at least low-level user privileges.

Key dates

06Disclosure timeline

June 9, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE