plugin

Easy Social Icons Vulnerabilities

32 known security issues reported for the Easy Social Icons WordPress plugin. Most recent disclosed Dec 13, 2024.

3 high 9 medium

Running Easy Social Icons on your site? Check whether your installed version is affected.

Scan your site free

Easy Social Icons [easy-social-icons] < 3.2.5

unknown

[en] Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Dec 13, 2024

CVE-2023-33998 on NVD →

Easy Social Icons [easy-social-icons] < 3.2.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cybernetikz Easy Social Icons allows Stored XSS.This issue affects Easy Social Icons: from n/a through 3.2.4.

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Nov 30, 2023

CVE-2023-48336 on NVD →

Easy Social Icons <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Easy Social Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-le...

CVSS:
6.4
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Nov 23, 2023

CVE-2023-48336 on NVD →

Easy Social Icons <= 3.2.4 - Missing Authorization via cnss_save_ajax_order

medium

The Easy Social Icons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cnss_save_ajax_order function in versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the order of...

CVSS:
4.3
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Nov 7, 2023

CVE-2023-33998 on NVD →

Easy Social Icons <= 3.2.0 - Authenticated (Admin+) Cross-Site Scripting and Missing Authorization Checks

high

The Easy Social Icons plugin for WordPress is vulnerable to Admin+ cross-site scripting and unauthenticated icon deletion in versions up to and including 3.2.0.

CVSS:
7.3
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Apr 11, 2022

Easy Social Icons <= 3.1.4 - Admin+ Cross-Site Scripting

medium

The Easy Social Icons plugin for WordPress is vulnerable to admin-level stored Cross-Site Scripting due to missing sanitization on several variables in versions up to, and including, 3.1.4.

CVSS:
5.5
Affected:
up to 3.1.4
Fixed in:
3.2.0
Disclosed:
Apr 11, 2022

Easy Social Icons <= 3.2.2 - Admin+ Cross-Site Scripting

medium

The Easy Social Icons plugin for WordPress was vulnerable to admin+ stored Cross-Site Scripting due to missing sanitization on a few parameters in versions up to, and including, 3.2.2.

CVSS:
5.5
Affected:
up to 3.2.2
Fixed in:
3.2.3
Disclosed:
Apr 11, 2022

Easy Social Icons [easy-social-icons] < 3.2.3

unknown

The Easy Social Icons plugin for WordPress was vulnerable to admin+ stored Cross-Site Scripting due to missing sanitization on a few parameters in versions up to, and including, 3.2.2.

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Apr 11, 2022

Easy Social Icons [easy-social-icons] < 3.2.1

unknown

[en] The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Apr 11, 2022

CVE-2022-0840 on NVD →

Easy Social Icons [easy-social-icons] < 3.2.1

unknown

The Easy Social Icons plugin for WordPress is vulnerable to Admin+ cross-site scripting and unauthenticated icon deletion in versions up to and including 3.2.0.

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Apr 11, 2022

Easy Social Icons [easy-social-icons] < 3.2.0

unknown

The Easy Social Icons plugin for WordPress is vulnerable to admin-level stored Cross-Site Scripting due to missing sanitization on several variables in versions up to, and including, 3.1.4.

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Apr 11, 2022

Easy Social Icons [easy-social-icons] < 3.2.1

unknown

[en] The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Apr 4, 2022

CVE-2022-0887 on NVD →

Easy Social Icons <= 3.2.0 - Admin+ Stored Cross-Site Scripting

medium

The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.

CVSS:
5.5
Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Mar 21, 2022

CVE-2022-0840 on NVD →

Easy Social Icons [easy-social-icons] < 3.2.1

unknown

Unauthenticated Arbitrary Icon Deletion vulnerability discovered by Jan w Oleju in WordPress Easy Social Icons (versions plugin <= 3.2.0).

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Mar 21, 2022

Easy Social Icons [easy-social-icons] < 3.2.0

unknown

Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Easy Social Icons plugin (versions <= 3.1.4).

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Mar 14, 2022

Easy Social Icons <= 3.1.3 - Admin+ SQL Injection

medium

The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

CVSS:
5.5
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Mar 8, 2022

CVE-2022-0887 on NVD →

Easy Social Icons <= 3.1.2 - Reflected Cross-Site Scripting

medium

The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
Sep 2, 2021

Easy Social Icons [easy-social-icons] < 3.1.3

unknown

The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Sep 2, 2021

Easy Social Icons [easy-social-icons] < 3.0.9

unknown

[en] The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Sep 2, 2021

CVE-2021-39322 on NVD →

Easy Social Icons [easy-social-icons] < 3.1.3

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Easy Social Icons plugin (versions <= 3.1.2).

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Sep 2, 2021

Easy Social Icons <= 3.0.9 - Reflected Cross-Site Scripting

medium

The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

CVSS:
6.1
Affected:
up to 3.0.9
Fixed in:
3.1.0
Disclosed:
Sep 1, 2021

Easy Social Icons <= 3.0.8 – Reflected Cross-Site Scripting

medium

The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

CVSS:
6.1
Affected:
up to 3.0.8
Fixed in:
3.0.9
Disclosed:
Sep 1, 2021

CVE-2021-39322 on NVD →

Easy Social Icons [easy-social-icons] < 3.1.0

unknown

The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Sep 1, 2021

Easy Social Icons <= 1.2.3.1 - SQL Injection

high

The Easy Social Icons plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in versions up to, and including, 1.2.3.1 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated Admin+ at...

CVSS:
7.2
Affected:
up to 1.2.3.1
Fixed in:
1.2.4
Disclosed:
Jul 22, 2015

Easy Social Icons [easy-social-icons] < 1.2.4

unknown

Because of this vulnerability, authenticated administrators can execute arbitrary SQL commands. Upgrade this plugin.

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Jul 22, 2015

Easy Social Icons [easy-social-icons] < 1.2.4

unknown

The Easy Social Icons plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in versions up to, and including, 1.2.3.1 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated Admin+ at...

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Jul 22, 2015

Easy Social Icons [easy-social-icons] < 1.2.3

unknown

[en] Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the image_file parameter in an edit action in the cnss_social_icon_add p...

Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Feb 25, 2015

CVE-2015-2084 on NVD →

Easy Social Icons <= 1.2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the image_file parameter in an edit action in the cnss_social_icon_add page t...

CVSS:
8.8
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Feb 19, 2015

CVE-2015-2084 on NVD →

Easy Social Icons [easy-social-icons] < 3.2.1

unknown

The plugin does not have authorisation and CSRF checks when deleting icons, allowing unauthenticated user to delete arbitrary icons

Affected:
up to 3.2.1
Fixed in:
3.2.1

Easy Social Icons [easy-social-icons] < 3.2.1

unknown
Affected:
up to 3.2.1
Fixed in:
3.2.1

Easy Social Icons [easy-social-icons] < 3.1.3

unknown

The plugin does not escape user input before outputting it back in attributes, leading to Reflected Cross-Site Scripting issues

Affected:
up to 3.1.3
Fixed in:
3.1.3

Easy Social Icons [easy-social-icons] < 1.2.4

unknown

The Easy Social Icons WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.

Affected:
up to 1.2.4
Fixed in:
1.2.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database