CVE-2023-0958
Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function
Severity Score
6.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to install select plugins from Inisev on vulnerable sites. CVE-2023-38514 appears to be a duplicate of this vulnerability.
*Credits:
Chloe Chamberland
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-02-22 CVE Reserved
- 2023-07-27 CVE Published
- 2024-09-27 CVE Updated
- 2024-11-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (23)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Backupbliss Search vendor "Backupbliss" | Backup Migration Search vendor "Backupbliss" for product "Backup Migration" | < 1.2.8 Search vendor "Backupbliss" for product "Backup Migration" and version " < 1.2.8" | wordpress |
Affected
| ||||||
Backupbliss Search vendor "Backupbliss" | Clone Search vendor "Backupbliss" for product "Clone" | < 2.3.8 Search vendor "Backupbliss" for product "Clone" and version " < 2.3.8" | wordpress |
Affected
| ||||||
Copy-delete-posts Search vendor "Copy-delete-posts" | Duplicate Post Search vendor "Copy-delete-posts" for product "Duplicate Post" | < 1.4.0 Search vendor "Copy-delete-posts" for product "Duplicate Post" and version " < 1.4.0" | wordpress |
Affected
| ||||||
Inisev Search vendor "Inisev" | Redirection Search vendor "Inisev" for product "Redirection" | < 1.1.4 Search vendor "Inisev" for product "Redirection" and version " < 1.1.4" | wordpress |
Affected
| ||||||
Inisev Search vendor "Inisev" | Rss Redirect \& Feedburner Alternative Search vendor "Inisev" for product "Rss Redirect \& Feedburner Alternative" | < 3.8 Search vendor "Inisev" for product "Rss Redirect \& Feedburner Alternative" and version " < 3.8" | wordpress |
Affected
| ||||||
Inisev Search vendor "Inisev" | Ssl Mixed Content Fix Search vendor "Inisev" for product "Ssl Mixed Content Fix" | < 3.2.4 Search vendor "Inisev" for product "Ssl Mixed Content Fix" and version " < 3.2.4" | wordpress |
Affected
| ||||||
Mypopups Search vendor "Mypopups" | Pop-up Search vendor "Mypopups" for product "Pop-up" | < 1.2.0 Search vendor "Mypopups" for product "Pop-up" and version " < 1.2.0" | wordpress |
Affected
| ||||||
Socialshare Search vendor "Socialshare" | Social Share Icons \& Social Share Buttons Search vendor "Socialshare" for product "Social Share Icons \& Social Share Buttons" | < 3.5.8 Search vendor "Socialshare" for product "Social Share Icons \& Social Share Buttons" and version " < 3.5.8" | wordpress |
Affected
| ||||||
Themecheck Search vendor "Themecheck" | Enhanced Text Widget Search vendor "Themecheck" for product "Enhanced Text Widget" | < 1.5.8 Search vendor "Themecheck" for product "Enhanced Text Widget" and version " < 1.5.8" | wordpress |
Affected
| ||||||
Themecheck Search vendor "Themecheck" | Ultimate Posts Widget Search vendor "Themecheck" for product "Ultimate Posts Widget" | < 2.2.5 Search vendor "Themecheck" for product "Ultimate Posts Widget" and version " < 2.2.5" | wordpress |
Affected
| ||||||
Ultimatelysocial Search vendor "Ultimatelysocial" | Social Media Share Buttons \& Social Sharing Icons Search vendor "Ultimatelysocial" for product "Social Media Share Buttons \& Social Sharing Icons" | < 2.8.2 Search vendor "Ultimatelysocial" for product "Social Media Share Buttons \& Social Sharing Icons" and version " < 2.8.2" | wordpress |
Affected
|