CVE-2026-4063: Social Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation
The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the addmenuitem() method hooked to adminmenu in all versions up to, and including, 4.5.8. This is due to the method performing wpinsertpost() and updatepostmeta() calls to create a sharing configuration without verifying the current user has administrator-level capabilities. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger the creation of a published wpzoom-sharing configuration post with default sharing button settings, which causes social sharing buttons to be automatically injected into all post content on the frontend via the thecontent filter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4063?
CVE-2026-4063 has a high severity due to its potential for unauthorized data modification.
How do I fix CVE-2026-4063?
To fix CVE-2026-4063, update the Social Icons Widget & Block plugin to a version later than 4.5.8.
Who is affected by CVE-2026-4063?
Any WordPress site using the Social Icons Widget & Block plugin version 4.5.8 or earlier is affected by CVE-2026-4063.
What types of attacks can CVE-2026-4063 lead to?
CVE-2026-4063 can lead to unauthorized sharing configuration changes, allowing improper data modification.
Is there a workaround for CVE-2026-4063?
As a temporary workaround for CVE-2026-4063, consider disabling the plugin until it is updated.