CVE-2023-7268

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets
Configurations

Configuration 1 (hide)

cpe:2.3:a:artplacer:artplacer_widget:*:*:*:*:*:wordpress:*:*

History

16 May 2025, 13:15

Type Values Removed Values Added
CWE CWE-862
First Time Artplacer
Artplacer artplacer Widget
References () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ - () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:artplacer:artplacer_widget:*:*:*:*:*:wordpress:*:*

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ - () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ -

01 Aug 2024, 13:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

19 Jul 2024, 13:01

Type Values Removed Values Added
Summary
  • (es) El complemento ArtPlacer Widget de WordPress anterior a 2.21.2 no cuenta con verificación de autorización al eliminar widgets, lo que permite a cualquier usuario autenticado, como el suscriptor, eliminar widgets arbitrarios.

19 Jul 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-19 06:15

Updated : 2025-05-16 13:15


NVD link : CVE-2023-7268

Mitre link : CVE-2023-7268

CVE.ORG link : CVE-2023-7268


JSON object : View

Products Affected

artplacer

  • artplacer_widget
CWE
CWE-862

Missing Authorization