CVE-2023-0958, CVE-2023-38514
The Ultimate Social Media Icons plugin before version 2.8.2 contains a vulnerability in its handle_installation function that fails to properly validate user permissions on the inisev_installation AJAX action. This flaw allows attackers with basic authenticated access, including those with subscriber-level privileges, to install plugins developed by Inisev without authorization. The missing capability check creates a significant security risk by enabling low-privileged users to extend site functionality beyond their intended scope.
Based on public CVE data (MITRE/NVD).