Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44602 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. |
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function | |
| Weaknesses | CWE-352 |
Thu, 03 Apr 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inisev enhanced Text Widget
|
|
| CPEs | cpe:2.3:a:inisev:enhanced_text_widget:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themecheck
Themecheck enhanced Text Widget |
Inisev enhanced Text Widget
|
Thu, 03 Apr 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inisev ultimate Posts Widget
|
|
| CPEs | cpe:2.3:a:inisev:ultimate_posts_widget:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themecheck ultimate Posts Widget
|
Inisev ultimate Posts Widget
|
Wed, 05 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:14:37.640Z
Reserved: 2023-07-27T16:08:30.895Z
Link: CVE-2023-3977
Updated: 2024-08-02T07:08:50.857Z
Status : Modified
Published: 2023-07-28T05:15:11.200
Modified: 2026-04-08T19:18:27.717
Link: CVE-2023-3977
No data.
OpenCVE Enrichment
No data.
EUVD