CVE-2023-7268

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets
Configurations

Configuration 1 (hide)

cpe:2.3:a:artplacer:artplacer_widget:*:*:*:*:*:wordpress:*:*

History

16 May 2025, 13:15

Type Values Removed Values Added
First Time Artplacer
Artplacer artplacer Widget
CWE CWE-862
CPE cpe:2.3:a:artplacer:artplacer_widget:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ - () https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ - Exploit, Third Party Advisory

Information

Published : 2024-07-19 06:15

Updated : 2025-05-16 13:15


NVD link : CVE-2023-7268

Mitre link : CVE-2023-7268

CVE.ORG link : CVE-2023-7268


JSON object : View

Products Affected

artplacer

  • artplacer_widget
CWE
CWE-862

Missing Authorization