The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/f8f84d47-49aa-4258-a8a6-3de8e7342623 | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/f8f84d47-49aa-4258-a8a6-3de8e7342623 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 08:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/f8f84d47-49aa-4258-a8a6-3de8e7342623 - Exploit, Third Party Advisory |
19 Jan 2024, 18:27
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-862 | |
References | () https://wpscan.com/vulnerability/f8f84d47-49aa-4258-a8a6-3de8e7342623 - Exploit, Third Party Advisory | |
First Time |
Kishorkhambu wp Custom Widget Area
Kishorkhambu |
|
CPE | cpe:2.3:a:kishorkhambu:wp_custom_widget_area:*:*:*:*:*:wordpress:*:* |
15 Jan 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-15 16:15
Updated : 2024-11-21 08:43
NVD link : CVE-2023-6066
Mitre link : CVE-2023-6066
CVE.ORG link : CVE-2023-6066
JSON object : View
Products Affected
kishorkhambu
- wp_custom_widget_area
CWE
CWE-862
Missing Authorization