The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/f8f84d47-49aa-4258-a8a6-3de8e7342623 | Exploit Third Party Advisory |
Configurations
History
19 Jan 2024, 18:27
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-01-15 16:15
Updated : 2024-01-19 18:27
NVD link : CVE-2023-6066
Mitre link : CVE-2023-6066
CVE.ORG link : CVE-2023-6066
JSON object : View
Products Affected
kishorkhambu
- wp_custom_widget_area
CWE
CWE-862
Missing Authorization
