plugin

Enhanced Text Widget Vulnerabilities

13 known security issues reported for the Enhanced Text Widget WordPress plugin. Most recent disclosed Dec 13, 2024.

6 medium

Running Enhanced Text Widget on your site? Check whether your installed version is affected.

Scan your site free

Enhanced Text Widget [enhanced-text-widget] < 1.5.8

unknown

[en] Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Dec 13, 2024

CVE-2023-38514 on NVD →

Enhanced Text Widget [enhanced-text-widget] < 1.5.9

unknown

[en] Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.5.8.

Affected:
up to 1.5.9
Fixed in:
1.5.9
Disclosed:
Dec 9, 2024

CVE-2023-23823 on NVD →

Enhanced Text Widget [enhanced-text-widget] < 1.6.4

unknown

[en] Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.6.3.

Affected:
up to 1.6.4
Fixed in:
1.6.4
Disclosed:
Dec 9, 2024

CVE-2023-49192 on NVD →

Inisev Analyst Module <= Various Versions - Missing Authorization

medium

Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 1.6.4
Fixed in:
1.6.5
Disclosed:
Apr 10, 2024

CVE-2024-31435 on NVD →

Enhanced Text Widget [enhanced-text-widget] < 1.6.6

unknown

[en] The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for e...

Affected:
up to 1.6.6
Fixed in:
1.6.6
Disclosed:
Mar 11, 2024

CVE-2024-0559 on NVD →

Enhanced Text Widget <= 1.6.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Enhanced Text Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget options in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary w...

CVSS:
4.4
Affected:
up to 1.6.5
Fixed in:
1.6.6
Disclosed:
Feb 20, 2024

CVE-2024-0559 on NVD →

Enhanced Text Widget <= 1.6.3 - Missing Authorization via etw_hide_admin_notification_callback

medium

The Enhanced Text Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the etw_hide_admin_notification_callback function in versions up to, and including, 1.6.3. This makes it possible for unauthenticated attackers to hide admin notifications.

CVSS:
5.3
Affected:
up to 1.6.3
Fixed in:
1.6.4
Disclosed:
Dec 1, 2023

CVE-2023-49192 on NVD →

Enhanced Text Widget [enhanced-text-widget] < 1.5.8

unknown

[en] Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permission...

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Jul 28, 2023

CVE-2023-0958 on NVD →

Enhanced Text Widget [enhanced-text-widget] < 1.5.8

unknown

[en] Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attack...

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Jul 28, 2023

CVE-2023-3977 on NVD →

Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function

medium

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers t...

CVSS:
4.3
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Jul 27, 2023

CVE-2023-3977 on NVD →

Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function

medium

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, su...

CVSS:
4.3
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Jul 27, 2023

CVE-2023-0958 on NVD →

Enhanced Text Widget <= 1.5.8 - Missing Authorization

medium

The Enhanced Text Widget plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on one of its functions in versions up to, and including, 1.5.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to make use of this functiona...

CVSS:
4.3
Affected:
up to 1.5.8
Fixed in:
1.5.9
Disclosed:
Jun 30, 2023

CVE-2023-23823 on NVD →

Enhanced Text Widget [enhanced-text-widget] < 1.6.5

unknown
Affected:
up to 1.6.5
Fixed in:
1.6.5

CVE-2024-31435 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database