Junglewise Threat Intelligence

CVE-2024-31435: Inisev Social Media & Share Icons missing authorization

CVE-2024-31435 · Severity: medium · CVSS 4.3 · Published 2026-06-17

Executive brief

The Social Media & Share Icons plugin for WordPress, which allows site owners to add social sharing buttons to their pages, contains a security flaw in its access control settings. An attacker could potentially trick a site administrator into performing unintended actions that modify the plugin's configuration. While this does not directly expose sensitive customer data, it could allow unauthorized changes to how social media features appear or function on the website.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the Inisev Social Media & Share Icons plugin (also known as ultimate-social-media-icons) for WordPress in versions up to and including 2.8.6. The flaw stems from broken access control and missing authorization checks on certain plugin functions. An unauthenticated remote attacker can exploit this by inducing a privileged user (such as an administrator) to perform an action via a crafted request, typically through Cross-Site Request Forgery (CSRF) or similar social engineering vectors. Successful exploitation allows the attacker to execute actions or modify settings that should be restricted to higher-privileged users. The issue is resolved in version 2.8.7.

Affected products

  • Inisev Social Media & Share Icons up to 2.8.6

Timeline

  • 2024-01-08: other: Reported by researcher Dhabaleshwar Das
  • 2024-04-26: advisory: Initial disclosure by Patchstack
  • 2024-04-26: patched: Version 2.8.7 released to address the vulnerability
  • 2026-06-17: disclosed: NVD publication date

References