3 results (0.006 seconds)

CVSS: 9.9EPSS: 0%CPEs: 1EXPL: 0

11 Feb 2025 — Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in MarketingFire Widget Options allows OS Command Injection.This issue affects Widget Options: from n/a through 4.1.0. The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.1.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server... • https://patchstack.com/database/wordpress/plugin/widget-options/vulnerability/wordpress-widget-options-plugin-4-1-0-arbitrary-code-execution-vulnerability?_s_id=cve • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

15 Jan 2025 — Missing Authorization vulnerability in Widget Options Team Widget Options allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Widget Options: from n/a through 4.0.8. The Widget Options plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the widgetopts_ajax_hide_rating() function in versions up to, and including, 4.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to... • https://patchstack.com/database/wordpress/plugin/widget-options/vulnerability/wordpress-widget-options-plugin-4-0-8-broken-access-control-to-notice-dimissal-vulnerability?_s_id=cve • CWE-862: Missing Authorization •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

19 Dec 2024 — Missing Authorization vulnerability in MarketingFire Widget Options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through 4.0.6.1. The Widget Options plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the widgetopts_save_widget_editor_cache() function in versions up to, and including, 4.0.6.1. This makes it possible for authenticated attackers, with contributor-level access and above, to save ca... • https://patchstack.com/database/wordpress/plugin/widget-options/vulnerability/wordpress-widget-options-plugin-4-0-6-1-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •