CVE-2024-30464
WordPress Social Icons Widget & Block by WPZOOM plugin <= 4.2.15 - Broken Access Control vulnerability
Record summary
CVE-2024-30464 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Social Icons Widget & Block by WPZOOMBrowse WPZOOM / Social Icons Widget & Block by WPZOOMsocial-icons-widget-by-wpzoomDefault status: unaffected | CVE List | Through 4.2.15 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWPZOOM Social Icons Widget <= 4.2.15 - Missing AuthorizationCVSS 4.3
WPZOOM Social Icons Widget & Block versions up to 4.2.15 contain a missing authorization vulnerability caused by insufficient access control in the widget and block, letting attackers perform unauthorized actions, exploit requires no special conditions.
Impact
Attackers can perform unauthorized actions, potentially leading to data tampering or privilege escalation.
Remediation
Update to version 4.2.16 or later.
Source: ProjectDiscovery