cve/2023/CVE-2023-7268.md
2024-07-25 21:25:12 +00:00

18 lines
748 B
Markdown

### [CVE-2023-7268](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7268)
![](https://img.shields.io/static/v1?label=Product&message=ArtPlacer%20Widget&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%202.21.2%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-862%20Missing%20Authorization&color=brighgreen)
### Description
The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets
### POC
#### Reference
- https://wpscan.com/vulnerability/9ac233dd-e00d-4aee-a41c-0de6e8aaefd7/
#### Github
No PoCs found on GitHub currently.