Enhanced Text Widget
Enhanced Text Widget has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2024; all 6 are fixed as of September 2026. Their average CVSS score is 4.5, and the most serious one scores 5.3 out of 10. 2023 was the busiest year with 4 disclosures.
The most common weakness is Missing Authorization, behind 4 of the records (67%). Other recurring categories include Cross-Site Request Forgery (CSRF), Cross-Site Scripting.
Every one of the 6 issues recorded for Enhanced Text Widget has a vendor fix available, so running the current release closes all known holes.
5 independent researchers contributed these findings, most of them (2) reported by Chloe Chamberland. Enhanced Text Widget is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2023-49192Enhanced Text Widget <= 1.6.3 - Missing Authorization via etw_hide_admin_notification_callback
Read the full analysisVulnerability Records

Enhanced Text Widget
Author
cl272
Try it out on your free dummy site: Click here => https://tastewp.com/plugins/enhanced-text-widget. (this trick works for all plugins in the WP repo – just replace “wordpress” with “tastewp” in the URL) Note: This is a classic widget type, in order for it to work on the latest version of WordPress you will need Classic Widgets plugin installed on your site. UPDATE: Plugin ownership changed for this plugin. We are currently evaluating possible enhancements for it. Stay tuned! If you have any suggestions yourself, please let us know in the Support Forum. An enhanced version of the default text widget where you may have Text, HTML, CSS, JavaScript, Flash, Shortcodes and/or PHP as content with linkable widget title. Options Title Title URL Widget CSS class Content supports Text, HTML, CSS, JavaScript, Flash, Shortcodes, and PHP Option to not display a title Option to open Title URL in new window Option to automatically add paragraphs to content Option to not output before/after_widget/title (bare widget) For questions, please ask in the support forum Support Enjoy this plugin? Send a tip to support development. This plugin is part of the Inisev product family – check out our other products.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C