### [CVE-2023-7268](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7268) ![](https://img.shields.io/static/v1?label=Product&message=ArtPlacer%20Widget&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%3C%202.21.2%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-862%20Missing%20Authorization&color=brighgreen) ### Description The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets ### POC #### Reference - https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/ #### Github No PoCs found on GitHub currently.