VYPR
Medium severity5.4NVD Advisory· Published Jun 12, 2024· Updated Apr 15, 2026

CVE-2023-40672

CVE-2023-40672

Description

Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing Authorization vulnerability in WordPress Sticky Social Media Icons plugin allows unprivileged users to execute higher-privileged actions.

The Sticky Social Media Icons plugin for WordPress suffers from a Missing Authorization vulnerability, categorized as a Broken Access Control issue. The root cause is the lack of proper capability or nonce token checks in one or more functions, which would normally prevent unauthorized access. This affects all versions from n/a through 2.1 [1].

An attacker, without needing any authentication or with only low-privilege access, can exploit this by sending crafted requests to the vulnerable endpoints. No special network position is required, making it exploitable remotely. The missing checks allow unauthenticated or low-privileged users to perform actions that should require higher privileges, such as administrative functions [1].

The impact is that an attacker could modify plugin settings, inject malicious content, or potentially take over the website. This type of vulnerability is frequently used in mass-exploit campaigns targeting thousands of WordPress sites, regardless of their size or popularity [1].

A patched version is available. As an immediate action, users should update the plugin to the latest version. If updating is not possible, administrators should contact their hosting provider or web developer for assistance [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.