Plugin Vulnerability Hub
Plugin 12 known issues Latest disclosed Nov 23, 2023

Easy Social Icons Vulnerabilities

Review known vulnerability records for the WordPress plugin Easy Social Icons (`easy-social-icons`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2023-48336 and CVE-2023-33998, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
12
High or Critical
3
Patch Coverage
100%
Last Updated
Jan 22, 2024
Related Security Guides

Use these guides while reviewing Easy Social Icons fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Easy Social Icons remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
7
1. Match the Package
Confirm the installed WordPress plugin slug is easy-social-icons before acting on any CVE from this cluster.
2. Sort by Severity
Start with 3 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
12 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Easy Social Icons CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
6
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2015-2084
Easy Social Icons <= 1.2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripti...
Stored Cross-Site Scripting Versions up to 1.2.2 1.2.3 CVSS 8.8
CVE-2023-48336
Easy Social Icons <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scriptin...
Stored Cross-Site Scripting Versions up to 3.2.4 3.2.5 CVSS 6.4
CVE-2021-39322
Easy Social Icons <= 3.0.8 – Reflected Cross-Site Scripting
Cross-Site Scripting Versions up to 3.0.8 3.0.9 CVSS 6.1
CVE-2022-0840
Easy Social Icons <= 3.2.0 - Admin+ Stored Cross-Site Scripting
Stored Cross-Site Scripting Versions before 3.2.1 3.2.1 CVSS 5.5
CVE-2022-0887
Easy Social Icons <= 3.1.3 - Admin+ SQL Injection
SQL Injection Versions up to 3.1.3 3.1.4 CVSS 5.5
CVE-2023-33998
Easy Social Icons <= 3.2.4 - Missing Authorization via cnss_save_ajax_order
Vulnerability Versions up to 3.2.4 3.2.5 CVSS 4.3
Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Easy Social Icons so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
12 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 3 high severity findings.
Recent CVEs
CVE-2023-48336 and CVE-2023-33998
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Easy Social Icons

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2023-48336
CVE-2023-48336: Easy Social Icons <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The Easy Social Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut...

Published
Nov 23, 2023
Patched Release
3.2.5
Affected Versions
Versions up to 3.2.4
Next Step
Update to 3.2.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-33998
CVE-2023-33998: Easy Social Icons <= 3.2.4 - Missing Authorization via cnss_save_ajax_order

The Easy Social Icons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cnss_save_ajax_order function in versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with subscriber-level...

Published
Nov 07, 2023
Patched Release
3.2.5
Affected Versions
Versions up to 3.2.4
Next Step
Update to 3.2.5 or newer if supported.
Plugin Medium Patched: Yes
Easy Social Icons <= 3.1.4 - Admin+ Cross-Site Scripting

The Easy Social Icons plugin for WordPress is vulnerable to admin-level stored Cross-Site Scripting due to missing sanitization on several variables in versions up to, and including, 3.1.4.

Published
Apr 11, 2022
Patched Release
3.2.0
Affected Versions
Versions up to 3.1.4
Next Step
Update to 3.2.0 or newer if supported.
Plugin High Patched: Yes
Easy Social Icons <= 3.2.0 - Authenticated (Admin+) Cross-Site Scripting and Missing Authorization Checks

The Easy Social Icons plugin for WordPress is vulnerable to Admin+ cross-site scripting and unauthenticated icon deletion in versions up to and including 3.2.0.

Published
Apr 11, 2022
Patched Release
3.2.1
Affected Versions
Versions up to 3.2.0
Next Step
Update to 3.2.1 or newer if supported.
Plugin Medium Patched: Yes
Easy Social Icons <= 3.2.2 - Admin+ Cross-Site Scripting

The Easy Social Icons plugin for WordPress was vulnerable to admin+ stored Cross-Site Scripting due to missing sanitization on a few parameters in versions up to, and including, 3.2.2.

Published
Apr 11, 2022
Patched Release
3.2.3
Affected Versions
Versions up to 3.2.2
Next Step
Update to 3.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-0840
CVE-2022-0840: Easy Social Icons <= 3.2.0 - Admin+ Stored Cross-Site Scripting

The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.

Published
Mar 21, 2022
Patched Release
3.2.1
Affected Versions
Versions before 3.2.1
Next Step
Update to 3.2.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-0887
CVE-2022-0887: Easy Social Icons <= 3.1.3 - Admin+ SQL Injection

The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

Published
Mar 08, 2022
Patched Release
3.1.4
Affected Versions
Versions up to 3.1.3
Next Step
Update to 3.1.4 or newer if supported.
Plugin Medium Patched: Yes
Easy Social Icons <= 3.1.2 - Reflected Cross-Site Scripting

The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb...

Published
Sep 02, 2021
Patched Release
3.1.3
Affected Versions
Versions up to 3.1.2
Next Step
Update to 3.1.3 or newer if supported.
Plugin Medium Patched: Yes
Easy Social Icons <= 3.0.9 - Reflected Cross-Site Scripting

The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...

Published
Sep 01, 2021
Patched Release
3.1.0
Affected Versions
Versions up to 3.0.9
Next Step
Update to 3.1.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-39322
CVE-2021-39322: Easy Social Icons <= 3.0.8 – Reflected Cross-Site Scripting

The Easy Social Icons plugin

Published
Sep 01, 2021
Patched Release
3.0.9
Affected Versions
Versions up to 3.0.8
Next Step
Update to 3.0.9 or newer if supported.
Plugin High Patched: Yes
Easy Social Icons <= 1.2.3.1 - SQL Injection

The Easy Social Icons plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in versions up to, and including, 1.2.3.1 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...

Published
Jul 22, 2015
Patched Release
1.2.4
Affected Versions
Versions up to 1.2.3.1
Next Step
Update to 1.2.4 or newer if supported.
Plugin High Patched: Yes CVE-2015-2084
CVE-2015-2084: Easy Social Icons <= 1.2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the image_file parameter in an edit a...

Published
Feb 19, 2015
Patched Release
1.2.3
Affected Versions
Versions up to 1.2.2
Next Step
Update to 1.2.3 or newer if supported.