Impact
The Social Images Widget plugin for WordPress contains a missing capability check in the options_update function. This flaw allows an unauthenticated user to send a forged request that deletes the plugin’s settings, potentially disrupting the site’s functionality and appearance. The vulnerability does not grant full administrative control but does enable loss of configuration data.
Affected Systems
The vulnerability affects the lyrathemes Social Images Widget plugin, versions up to and including 2.1. All installations running any of these versions are susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires a crafted request to the options_update endpoint and relies on a user (for example, a site administrator) clicking a malicious link or otherwise submitting the forged request. No public exploitation evidence is available, but missing authorization check makes the plugin’s settings deletion an accessible attack vector.
OpenCVE Enrichment