CVE-2023-3977
The ultimate-social-media-icons plugin prior to version 2.8.2 contains a Cross-Site Request Forgery vulnerability in its plugin installation functionality. Attackers can exploit the missing nonce verification on the handle_installation function to trick site administrators into installing arbitrary plugins from a predefined list by crafting malicious requests. An unauthenticated threat actor could leverage this flaw to install unwanted plugins if they can convince an admin to interact with a specially crafted link. This vulnerability affects multiple plugin versions from the affected developer.
Based on public CVE data (MITRE/NVD).