CVE-2024-2189: Social Icons Widget & Block < 4.2.18 - Admin+ Stored XSS
The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2189?
CVE-2024-2189 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2189?
To fix CVE-2024-2189, update the Social Icons Widget & Block by WPZOOM plugin to version 4.2.18 or later.
Who is affected by CVE-2024-2189?
CVE-2024-2189 affects users of the Social Icons Widget & Block by WPZOOM plugin version before 4.2.18, particularly those with admin privileges.
What type of vulnerability is CVE-2024-2189?
CVE-2024-2189 is a Stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2024-2189 be exploited by low privilege users?
No, CVE-2024-2189 requires high privilege users, such as admins, to exploit the vulnerability.