CVE Database /
CVE-2024-30464
CVE · Medium
CVE-2024-30464 — WPZOOM Connect: Social Icons Widget, Share Buttons & Click to Chat [social-icons-widget-by-wpzoom] < 4.2.16
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-30464
|
WPZOOM Connect: Social Icons Widget, Share Buttons & Click to Chat [social-icons-widget-by-wpzoom] < 4.2.16 |
Missing Authorization |
Medium
5.4
|
< 4.2.16
|
4.2.16 |
2024-03-28 |
—
|
CVE-2024-30464
The Social Icons Widget & Block by WPZOOM plugin before version 4.2.16 contains a broken access control vulnerability that allows unauthorized users to perform actions restricted to privileged accounts. The flaw stems from missing authorization and authentication checks, along with absent nonce token validation in a particular function. This issue has been resolved in version 4.2.16 and later releases.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings