plugin

Social Icons Widget By Wpzoom Vulnerabilities

6 known security issues reported for the Social Icons Widget By Wpzoom WordPress plugin. Most recent disclosed Mar 13, 2026.

4 medium

Running Social Icons Widget By Wpzoom on your site? Check whether your installed version is affected.

Scan your site free

Social Icons Widget & Block by WPZOOM - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation vulnerability

medium

Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation vulnerability

CVSS:
4.3
Affected:
up to 4.5.8
Fixed in:
4.5.9
Disclosed:
Mar 13, 2026

Social Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation

medium

The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8. This is due to the method performing wp_insert_post() and update_post_meta() ca...

CVSS:
4.3
Affected:
up to 4.5.8
Fixed in:
4.5.9
Disclosed:
Mar 12, 2026

CVE-2026-4063 on NVD →

Social Icons &amp; Sharing Buttons by WPZOOM [social-icons-widget-by-wpzoom] < 4.2.16

unknown

[en] Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

Affected:
up to 4.2.16
Fixed in:
4.2.16
Disclosed:
Jun 9, 2024

CVE-2024-30464 on NVD →

Social Icons &amp; Sharing Buttons by WPZOOM [social-icons-widget-by-wpzoom] < 4.2.18

unknown

[en] The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite set...

Affected:
up to 4.2.18
Fixed in:
4.2.18
Disclosed:
May 21, 2024

CVE-2024-2189 on NVD →

Social Icons Widget & Block <= 4.2.17 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...

CVSS:
4.4
Affected:
up to 4.2.17
Fixed in:
4.2.18
Disclosed:
Apr 30, 2024

CVE-2024-2189 on NVD →

Social Icons Widget & Block by WPZOOM <= 4.2.15 - Missing Authorization

medium

The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the zoom_ajax_set_pointer_transient() function in versions up to, and including, 4.2.15. This makes it possible for authenticated attackers, with subscriber-level access and above, to...

CVSS:
4.3
Affected:
up to 4.2.15
Fixed in:
4.2.16
Disclosed:
Mar 28, 2024

CVE-2024-30464 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database