Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12943 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to install select plugins from Inisev on vulnerable sites. CVE-2023-38514 appears to be a duplicate of this vulnerability. |
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function | |
| Weaknesses | CWE-862 |
Thu, 03 Apr 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inisev enhanced Text Widget
|
|
| CPEs | cpe:2.3:a:inisev:enhanced_text_widget:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themecheck
Themecheck enhanced Text Widget |
Inisev enhanced Text Widget
|
Thu, 03 Apr 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inisev ultimate Posts Widget
|
|
| CPEs | cpe:2.3:a:inisev:ultimate_posts_widget:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themecheck ultimate Posts Widget
|
Inisev ultimate Posts Widget
|
Fri, 27 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:24:39.864Z
Reserved: 2023-02-22T16:05:20.057Z
Link: CVE-2023-0958
Updated: 2024-08-02T05:32:46.051Z
Status : Modified
Published: 2023-07-28T05:15:09.597
Modified: 2026-04-08T19:18:04.243
Link: CVE-2023-0958
No data.
OpenCVE Enrichment
No data.
EUVD