CVE-2023-7268

T

he ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets

Configurations

Configuration 1 (hide)

cpe:2.3:a:artplacer:artplacer_widget:*:*:*:*:*:wordpress:*:*

History

16 May 2025, 13:15

Type Values Removed Values Added
First Time Artplacer
Artplacer artplacer Widget
CPE cpe:2.3:a:artplacer:artplacer_widget:*:*:*:*:*:wordpress:*:*
CWE CWE-862
References () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ - () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ - Exploit, Third Party Advisory

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ - () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ -

01 Aug 2024, 13:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

19 Jul 2024, 13:01

Type Values Removed Values Added
Summary
  • (es) El complemento ArtPlacer Widget de WordPress anterior a 2.21.2 no cuenta con verificación de autorización al eliminar widgets, lo que permite a cualquier usuario autenticado, como el suscriptor, eliminar widgets arbitrarios.

19 Jul 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-19 06:15

Updated : 2025-05-16 13:15


NVD link : CVE-2023-7268

Mitre link : CVE-2023-7268

CVE.ORG link : CVE-2023-7268


JSON object : View

Products Affected
CWE
CWE-862

Missing Authorization