Enhanced Text Widget [enhanced-text-widget] < 1.5.8
unknown
[en] Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Dec 13, 2024
CVE-2023-38514 on NVD →
Enhanced Text Widget [enhanced-text-widget] < 1.5.9
unknown
[en] Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.5.8.
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.9
- Disclosed:
- Dec 9, 2024
CVE-2023-23823 on NVD →
Enhanced Text Widget [enhanced-text-widget] < 1.6.4
unknown
[en] Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.6.3.
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Dec 9, 2024
CVE-2023-49192 on NVD →
Inisev Analyst Module <= Various Versions - Missing Authorization
medium
Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.5
- Disclosed:
- Apr 10, 2024
CVE-2024-31435 on NVD →
Enhanced Text Widget [enhanced-text-widget] < 1.6.6
unknown
[en] The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for e...
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Mar 11, 2024
CVE-2024-0559 on NVD →
Enhanced Text Widget <= 1.6.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Enhanced Text Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget options in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary w...
- CVSS:
- 4.4
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.6
- Disclosed:
- Feb 20, 2024
CVE-2024-0559 on NVD →
Enhanced Text Widget <= 1.6.3 - Missing Authorization via etw_hide_admin_notification_callback
medium
The Enhanced Text Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the etw_hide_admin_notification_callback function in versions up to, and including, 1.6.3. This makes it possible for unauthenticated attackers to hide admin notifications.
- CVSS:
- 5.3
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Dec 1, 2023
CVE-2023-49192 on NVD →
Enhanced Text Widget [enhanced-text-widget] < 1.5.8
unknown
[en] Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permission...
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Jul 28, 2023
CVE-2023-0958 on NVD →
Enhanced Text Widget [enhanced-text-widget] < 1.5.8
unknown
[en] Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attack...
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Jul 28, 2023
CVE-2023-3977 on NVD →
Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers t...
- CVSS:
- 4.3
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Jul 27, 2023
CVE-2023-3977 on NVD →
Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, su...
- CVSS:
- 4.3
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Jul 27, 2023
CVE-2023-0958 on NVD →
Enhanced Text Widget <= 1.5.8 - Missing Authorization
medium
The Enhanced Text Widget plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on one of its functions in versions up to, and including, 1.5.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to make use of this functiona...
- CVSS:
- 4.3
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.9
- Disclosed:
- Jun 30, 2023
CVE-2023-23823 on NVD →
Enhanced Text Widget [enhanced-text-widget] < 1.6.5
unknown
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
CVE-2024-31435 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database