ArtPlacer Widget [artplacer-widget] <= 2.23.1 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Stored XSS.This issue affects ArtPlacer Widget: from n/a through <= 2.23.1.
- Affected:
- up to 2.23.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24555 on NVD →
ArtPlacer Widget <= 2.23.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ArtPlacer Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 2.23.2
- Fixed in:
- 2.23.3
- Disclosed:
- Jan 22, 2026
CVE-2026-24555 on NVD →
ArtPlacer Widget [artplacer-widget] <= 2.22.9.2 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Blind SQL Injection.This issue affects ArtPlacer Widget: from n/a through <= 2.22.9.2.
- Affected:
- up to 2.22.9.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67517 on NVD →
ArtPlacer Widget <= 2.22.9.2 - Authenticated (Contributor+) SQL Injection
medium
The ArtPlacer Widget plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.22.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 6.5
- Affected:
- up to 2.22.9.2
- Fixed in:
- 2.23
- Disclosed:
- Nov 23, 2025
CVE-2025-67517 on NVD →
ArtPlacer Widget [artplacer-widget] < 2.21.2
unknown
[en] The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
- Affected:
- up to 2.21.2
- Fixed in:
- 2.21.2
- Disclosed:
- Jul 19, 2024
CVE-2023-7269 on NVD →
ArtPlacer Widget [artplacer-widget] < 2.21.2
unknown
[en] The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets
- Affected:
- up to 2.21.2
- Fixed in:
- 2.21.2
- Disclosed:
- Jul 19, 2024
CVE-2023-7268 on NVD →
ArtPlacer Widget <= 2.21.1 - Cross-Site Request Forgery
medium
The ArtPlacer Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.21.1. This is due to missing or incorrect nonce validation on the 'add-art-placer' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts...
- CVSS:
- 6.1
- Affected:
- up to 2.21.1
- Fixed in:
- 2.21.2
- Disclosed:
- Jun 28, 2024
CVE-2023-7269 on NVD →
ArtPlacer Widget <= 2.21.1 - Missing Authorization to Widget Deletion
medium
The ArtPlacer Widget plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the artplacer_del AJAX action in all versions up to, and including, 2.21.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary widgets.
- CVSS:
- 4.3
- Affected:
- up to 2.21.1
- Fixed in:
- 2.21.2
- Disclosed:
- Jun 28, 2024
CVE-2023-7268 on NVD →
ArtPlacer Widget [artplacer-widget] < 2.20.7
unknown
[en] The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged editor (or above)
- Affected:
- up to 2.20.7
- Fixed in:
- 2.20.7
- Disclosed:
- Jan 16, 2024
CVE-2023-6373 on NVD →
ArtPlacer Widget <= 2.20.6 - Authenticated (Editor+) SQL Injection
high
The ArtPlacer Widget plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 2.20.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with edi...
- CVSS:
- 8.8
- Affected:
- up to 2.20.6
- Fixed in:
- 2.20.7
- Disclosed:
- Dec 7, 2023
CVE-2023-6373 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database