Back

MEDIUM

Social Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation

Published Mar 13, 2026

Description

The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8. This is due to the method performing wp_insert_post() and update_post_meta() calls to create a sharing configuration without verifying the current user has administrator-level capabilities. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger the creation of a published wpzoom-sharing configuration post with default sharing button settings, which causes social sharing buttons to be automatically injected into all post content on the frontend via the the_content filter.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Wordfence
Published Mar 13, 2026
Updated Apr 8, 2026
Reserved Mar 12, 2026

CISA Vulnrichment

Updated Mar 13, 2026

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Wordfence
Published Mar 13, 2026
Updated Apr 8, 2026

GitHub

No data