CVE-2026-4063Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8. This is due to the method performing wp_insert_post() and update_post_meta() calls to create a sharing configuration without verifying the current user has administrator-level capabilities. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger the creation of a published wpzoom-sharing configuration post with default sharing button settings, which causes social sharing buttons to be automatically injected into all post content on the frontend via the the_content filter.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-13: 2Technical Details · 2026-03-13: 203-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4063 - WPZOOM Social Icons Widget & Block Unauthenticated Data Modification Vulnerability Intel Report: https://ift.tt/IeHVCdX

    Post summary

    The alert announces CVE-2026-4063, an unauthenticated data modification vulnerability affecting the WPZOOM Social Icons Widget, and points to an Intel Report for further details.

    0000082
    340 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4063 The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() … https://www.cve.org/CVERecord?id=CVE-2026-4063

    Post summary

    A new CVE (CVE-2026-4063) has been disclosed for the WPZOOM Social Icons Widget & Block, revealing that a missing capability check in add_menu_item() permits unauthorized data modification.

    00000128
    56.7K followersView on X

Explore more