Showing 1 vulnerability on this page for WPZOOM Social Feed Widget & Block

Signals CISA KEV Ransomware Nuclei
wpzoom vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WPZOOM Social Feed Widget & Block <= 2.1.13 - Missing Authorization to Authenticated (Subscriber+) Instagram Image Deletion

The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all Instagram images installed on the site.

CWE-862Apr 13, 2024
CVSS4.3v3.1EPSS0.465%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX