CVE-2024-3662: WPZOOM Social Feed Widget & Block <= 2.1.13 - Missing Authorization to Authenticated (Subscriber+) Instagram Image Deletion
The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoominstagramcleardata() function in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all Instagram images installed on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3662?
CVE-2024-3662 has a medium severity level due to unauthorized access risks.
How do I fix CVE-2024-3662?
To fix CVE-2024-3662, update the WPZOOM Social Feed Widget & Block plugin to version 2.1.14 or later.
Who is affected by CVE-2024-3662?
CVE-2024-3662 affects all users of the WPZOOM Social Feed Widget & Block plugin up to version 2.1.13.
Can CVE-2024-3662 be exploited by low-level users?
Yes, CVE-2024-3662 can be exploited by authenticated attackers with subscriber-level access.
What kind of access does CVE-2024-3662 allow an attacker?
CVE-2024-3662 allows an attacker to perform unauthorized actions due to a lack of capability checks.