PT-2024-12460 · Unknown+1 · Inisev Social Media & Share Icons+1

István Márton

·

Published

2024-12-13

·

Updated

2024-12-16

·

CVE-2023-34009

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Inisev Social Media & Share Icons versions 2.8.1 and earlier Ultimate Social Media Icons plugin for WordPress versions 2.8.1 and earlier
Description A high-severity issue affects the Ultimate Social Media Icons plugin for WordPress, allowing broken access control via CSRF due to missing authorization. This issue can be exploited by incorrectly configured access control security levels. Remediation is crucial to secure the site.
Recommendations For Inisev Social Media & Share Icons versions 2.8.1 and earlier: Update to the latest version to secure your site. For Ultimate Social Media Icons plugin for WordPress versions 2.8.1 and earlier: Update to the latest version to secure your site. As a temporary workaround, consider restricting access to vulnerable components until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-34009

Affected Products

Inisev Social Media & Share Icons
Ultimate Social Media Icons