Record summary

CVE-2024-30464 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Social Icons Widget & Block by WPZOOM

Browse WPZOOM / Social Icons Widget & Block by WPZOOMsocial-icons-widget-by-wpzoom

Default status: unaffected

CVE ListThrough 4.2.15affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWPZOOM Social Icons Widget <= 4.2.15 - Missing AuthorizationCVSS 4.3

WPZOOM Social Icons Widget & Block versions up to 4.2.15 contain a missing authorization vulnerability caused by insufficient access control in the widget and block, letting attackers perform unauthorized actions, exploit requires no special conditions.

Impact

Attackers can perform unauthorized actions, potentially leading to data tampering or privilege escalation.

Remediation

Update to version 4.2.16 or later.

WeaknessesCWE-862
Authorspussycat0x
Template tagscvecve2024wordpresswpwp-pluginwpzoomauthenticated
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Source: ProjectDiscovery

References

2