CVE Database
/

CVE-2023-6066

Back to search

CVE-2023-6066

Published: Jan 15, 2024

Modified: Jan 9, 2026

PUBLISHED

Description

The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.

VendorProductVersions

Unknown

WP Custom Widget area

affected
0 - <= 1.2.5

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now