plugin

Artplacer Widget Vulnerabilities

10 known security issues reported for the Artplacer Widget WordPress plugin. Most recent disclosed Jan 23, 2026.

1 high 4 medium

Running Artplacer Widget on your site? Check whether your installed version is affected.

Scan your site free

ArtPlacer Widget [artplacer-widget] <= 2.23.1 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Stored XSS.This issue affects ArtPlacer Widget: from n/a through <= 2.23.1.

Affected:
up to 2.23.1
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24555 on NVD →

ArtPlacer Widget <= 2.23.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ArtPlacer Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 2.23.2
Fixed in:
2.23.3
Disclosed:
Jan 22, 2026

CVE-2026-24555 on NVD →

ArtPlacer Widget [artplacer-widget] <= 2.22.9.2 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Blind SQL Injection.This issue affects ArtPlacer Widget: from n/a through <= 2.22.9.2.

Affected:
up to 2.22.9.2
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67517 on NVD →

ArtPlacer Widget <= 2.22.9.2 - Authenticated (Contributor+) SQL Injection

medium

The ArtPlacer Widget plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.22.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
6.5
Affected:
up to 2.22.9.2
Fixed in:
2.23
Disclosed:
Nov 23, 2025

CVE-2025-67517 on NVD →

ArtPlacer Widget [artplacer-widget] < 2.21.2

unknown

[en] The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

Affected:
up to 2.21.2
Fixed in:
2.21.2
Disclosed:
Jul 19, 2024

CVE-2023-7269 on NVD →

ArtPlacer Widget [artplacer-widget] < 2.21.2

unknown

[en] The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets

Affected:
up to 2.21.2
Fixed in:
2.21.2
Disclosed:
Jul 19, 2024

CVE-2023-7268 on NVD →

ArtPlacer Widget <= 2.21.1 - Cross-Site Request Forgery

medium

The ArtPlacer Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.21.1. This is due to missing or incorrect nonce validation on the 'add-art-placer' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts...

CVSS:
6.1
Affected:
up to 2.21.1
Fixed in:
2.21.2
Disclosed:
Jun 28, 2024

CVE-2023-7269 on NVD →

ArtPlacer Widget <= 2.21.1 - Missing Authorization to Widget Deletion

medium

The ArtPlacer Widget plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the artplacer_del AJAX action in all versions up to, and including, 2.21.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary widgets.

CVSS:
4.3
Affected:
up to 2.21.1
Fixed in:
2.21.2
Disclosed:
Jun 28, 2024

CVE-2023-7268 on NVD →

ArtPlacer Widget [artplacer-widget] < 2.20.7

unknown

[en] The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged editor (or above)

Affected:
up to 2.20.7
Fixed in:
2.20.7
Disclosed:
Jan 16, 2024

CVE-2023-6373 on NVD →

ArtPlacer Widget <= 2.20.6 - Authenticated (Editor+) SQL Injection

high

The ArtPlacer Widget plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 2.20.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with edi...

CVSS:
8.8
Affected:
up to 2.20.6
Fixed in:
2.20.7
Disclosed:
Dec 7, 2023

CVE-2023-6373 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database