CVE-2023-3977
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected (10)
Products: Backupbliss: Backup Migration, Clone · Copy Delete Posts: Duplicate Post · Inisev: Enhanced Text Widget, Redirection, Rss Redirect & Feedburner Alternative, Ssl Mixed Content Fix, Ultimate Posts Widget · +2 more
Show all products
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.8 | |
| Before 2.3.8 | |
| Before 1.4.0 | |
| Before 1.5.8 | |
| Before 1.1.4 | |
| Before 3.8 | |
| Before 3.2.4 | |
| Before 2.2.5 | |
| Before 1.2.0 | |
| Before 3.5.8 |
References (46)
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Exploit
Source: security@wordfence.com
Patch
Source: security@wordfence.com
Patch
Source: security@wordfence.com
Patch
Source: security@wordfence.com
Patch
Source: security@wordfence.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.