The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-07-19 06:15
Updated : 2025-05-16 13:15
NVD link : CVE-2023-7268
Mitre link : CVE-2023-7268
CVE.ORG link : CVE-2023-7268
JSON object : View
Products Affected
artplacer
- artplacer_widget
CWE
CWE-862
Missing Authorization
