Lucene search

K
cve[email protected]CVE-2023-3977
HistoryJul 28, 2023 - 5:15 a.m.

CVE-2023-3977

2023-07-2805:15:11
web.nvd.nist.gov
14
wordpress
inisev
csrf
authorization
plugin installation
vulnerability
nvd
cve-2023-3977

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.4%

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Affected configurations

Vulners
NVD
Node
steve85bssl_mixed_content_fixRange3.2.3
OR
copydeletepostsduplicate_postRange1.3.9
OR
socialshareprosocial_share_icons_\&_social_share_buttonsRange3.5.7
OR
cl272ultimate_posts_widgetRange2.2.4
OR
migratebackup_migrationRange1.2.7
OR
popupspop-upRange1.1.9
OR
socialduderedirectionRange1.1.3
OR
migratecloneRange2.3.7
OR
socialdudesocial_media_share_buttons_\&_social_sharing_iconsRange2.8.1
OR
s-feedsrss_redirect_\&_feedburner_alternativeRange3.7
OR
cl272enhanced_text_widgetRange1.5.7

CNA Affected

[
  {
    "vendor": "steve85b",
    "product": "SSL Mixed Content Fix",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "3.2.3",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "copydeleteposts",
    "product": "Duplicate Post",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "1.3.9",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "socialsharepro",
    "product": "Social Share Icons & Social Share Buttons",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "3.5.7",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "cl272",
    "product": "Ultimate Posts Widget",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "2.2.4",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "migrate",
    "product": "Backup Migration",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "1.2.7",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "popups",
    "product": "Pop-up",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "1.1.9",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "socialdude",
    "product": "Redirection",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "1.1.3",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "migrate",
    "product": "Clone",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "2.3.7",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "socialdude",
    "product": "Social Media Share Buttons & Social Sharing Icons",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "2.8.1",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "s-feeds",
    "product": "RSS Redirect & Feedburner Alternative",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "3.7",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "cl272",
    "product": "Enhanced Text Widget",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "1.5.7",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

References

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.4%

Related for CVE-2023-3977