ZeroHour

CVE-2023-6066

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p32
Published
()
Modified
Description

The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.

Vendors
kishorkhambu
Products
wp custom widget area
Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.