Looks like it has the potential for anyone to change the order.
Should you not be using nonces and checking the user is a valid logged in user?
http://codex.wordpress.org/WordPress_Nonces
http://codex.wordpress.org/Function_Reference/is_user_logged_in
http://wordpress.org/extend/plugins/floating-social-media-icon/