What this page helps you verify fast
This hub clusters tracked records for Easy Social Icons so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Easy Social Icons (`easy-social-icons`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2023-48336 and CVE-2023-33998, so operators can jump from disclosure to patch validation without scanning the full feed first.
Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.
Review patch cadence, privileged access, XML-RPC exposure, backups, and monitoring controls.
Use ownership, update testing, least privilege, and removal criteria to reduce plugin risk.
Compare scanner coverage for plugin CVEs, version detection, alert noise, and remediation workflow.
Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.
Affected range: Versions up to 1.2.2. Fixed version: 1.2.3.
Affected range: Versions up to 3.2.4. Fixed version: 3.2.5.
Affected range: Versions up to 3.0.8. Fixed version: 3.0.9.
Affected range: Versions before 3.2.1. Fixed version: 3.2.1.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
| Tracked CVE | Issue Type | Affected Versions | Fixed Version | CVSS |
|---|---|---|---|---|
|
CVE-2015-2084
Easy Social Icons <= 1.2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripti...
|
Stored Cross-Site Scripting | Versions up to 1.2.2 | 1.2.3 | CVSS 8.8 |
|
CVE-2023-48336
Easy Social Icons <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scriptin...
|
Stored Cross-Site Scripting | Versions up to 3.2.4 | 3.2.5 | CVSS 6.4 |
|
CVE-2021-39322
Easy Social Icons <= 3.0.8 – Reflected Cross-Site Scripting
|
Cross-Site Scripting | Versions up to 3.0.8 | 3.0.9 | CVSS 6.1 |
|
CVE-2022-0840
Easy Social Icons <= 3.2.0 - Admin+ Stored Cross-Site Scripting
|
Stored Cross-Site Scripting | Versions before 3.2.1 | 3.2.1 | CVSS 5.5 |
|
CVE-2022-0887
Easy Social Icons <= 3.1.3 - Admin+ SQL Injection
|
SQL Injection | Versions up to 3.1.3 | 3.1.4 | CVSS 5.5 |
|
CVE-2023-33998
Easy Social Icons <= 3.2.4 - Missing Authorization via cnss_save_ajax_order
|
Vulnerability | Versions up to 3.2.4 | 3.2.5 | CVSS 4.3 |
Easy Social Icons <= 1.2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Easy Social Icons <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
Easy Social Icons <= 3.0.8 – Reflected Cross-Site Scripting
Easy Social Icons <= 3.2.0 - Admin+ Stored Cross-Site Scripting
Easy Social Icons <= 3.1.3 - Admin+ SQL Injection
Easy Social Icons <= 3.2.4 - Missing Authorization via cnss_save_ajax_order
This hub clusters tracked records for Easy Social Icons so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Easy Social Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.4 due to insufficient input sa...
The Easy Social Icons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cnss_save_ajax_order function in versions up to, and in...
The Easy Social Icons plugin for WordPress is vulnerable to admin-level stored Cross-Site Scripting due to missing sanitization on several variables in versions up to, and including, 3.1.4.
Sorted by latest disclosure date so newly published issues surface first.
The Easy Social Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut...
The Easy Social Icons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cnss_save_ajax_order function in versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with subscriber-level...
The Easy Social Icons plugin for WordPress is vulnerable to admin-level stored Cross-Site Scripting due to missing sanitization on several variables in versions up to, and including, 3.1.4.
The Easy Social Icons plugin for WordPress is vulnerable to Admin+ cross-site scripting and unauthenticated icon deletion in versions up to and including 3.2.0.
The Easy Social Icons plugin for WordPress was vulnerable to admin+ stored Cross-Site Scripting due to missing sanitization on a few parameters in versions up to, and including, 3.2.2.
The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.
The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.
The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb...
The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
The Easy Social Icons plugin
The Easy Social Icons plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in versions up to, and including, 1.2.3.1 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...
Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the image_file parameter in an edit a...