
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4063 is a missing authorization vulnerability in the Social Icons Widget & Block by WPZOOM plugin for WordPress, affecting all versions up to and including 4.5.8. The flaw allows authenticated attackers with Subscriber-level access or above to perform unauthorized data modification by triggering the creation of a published sharing configuration post. It was published on March 13, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) in the add_menu_item() method, which is hooked to the WordPress admin_menu action. This method calls wp_insert_post() and update_post_meta() to create a wpzoom-sharing configuration post without verifying that the current user holds administrator-level capabilities. Any authenticated user with Subscriber-level access or above can trigger this action, causing a published sharing configuration post to be created with default settings. Once created, social sharing buttons are automatically injected into all post content on the frontend via the the_content filter (Wordfence, ENISA EUVD).
Successful exploitation results in unauthorized modification of site content — specifically, social sharing buttons being injected into all post content visible to frontend visitors. There is no confidentiality or availability impact; the integrity impact is limited to this unsolicited content injection. While not a critical threat, it can affect site appearance and user trust, and may be used to inject unwanted third-party social media tracking elements across an entire WordPress site (Wordfence, ENISA EUVD).
No public exploit code or in-the-wild exploitation has been reported for CVE-2026-4063. The EPSS score is approximately 0.028%, indicating a low probability of exploitation in the near term. The vulnerability requires authentication (Subscriber-level or above), which limits the attack surface. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, ENISA EUVD).
admin_menu hook to fire, invoking the add_menu_item() method in the WPZOOM_Social_Sharing_Buttons class.wp_insert_post() and update_post_meta() without capability verification, creating a published wpzoom-sharing configuration post with default sharing button settings.the_content filter (Wordfence).wpzoom-sharing with post_status = publish created by a low-privilege user account (e.g., Subscriber role).admin_menu hooks or plugin-specific admin endpoints.wpzoom-sharing post meta entries created at an unexpected time or by an unexpected user (Wordfence).Users should update the Social Icons Widget & Block by WPZOOM plugin to a version beyond 4.5.8, which includes the fix adding proper capability checks in the add_menu_item() method. The patch is available in the plugin's trunk repository (changeset 3481444) (WordPress Plugin Changeset). As a temporary workaround, site administrators can restrict user registration or remove Subscriber-level accounts if not needed, or deactivate the plugin until the update is applied.
The vulnerability was discovered and disclosed by Wordfence, which assigned the CVE and published the initial advisory. Sucuri included it in their March 2026 vulnerability patch roundup, noting it as part of a broader set of WordPress plugin issues addressed that month (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."