WP Custom Widget area <= 1.2.5 - Missing Authorization

2023-10-03 00:00
Abdi Pranata

Strategic Overview

Status
Unpatched
Affected PluginWP Custom Widget area
Affected Version<= 1.2.5
CVSS4.3Medium
CVECVE-2023-45045
View all WP Custom Widget area vulnerabilities

Vulnerability Overview

The WP Custom Widget area plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions corresponding to AJAX actions in versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to make use of functionality intended for users with higher privileges. This can lead to the deletion and modification of widgets and menus created using the plugin. CVE-2023-6066 may be a duplicate of this issue.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C