The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/f8f84d47-49aa-4258-a8a6-3de8e7342623 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-01-15 16:15
Updated : 2024-01-19 18:27
NVD link : CVE-2023-6066
Mitre link : CVE-2023-6066
CVE.ORG link : CVE-2023-6066
JSON object : View
Products Affected
kishorkhambu
- wp_custom_widget_area
CWE
CWE-862
Missing Authorization