Description
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2023-07-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44602 Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
References
Link Providers
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.7/includes/banner/misc.php#L427 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.8/includes/banner/misc.php#L434 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.3.8/banner/misc.php#L426 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.4.0/banner/misc.php#L434 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.6/banner/misc.php#L339 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.7/banner/misc.php#L351 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/feedburner-alternative-and-rss-redirect/tags/3.7/modules/banner/misc.php#L427 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/http-https-remover/tags/3.2.3/banner/misc.php#L427 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.1.9/modules/banner/misc.php#L427 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.2.0/modules/banner/misc.php#L432 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/redirect-redirection/tags/1.1.3/includes/banner/misc.php#L427 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.4/banner/misc.php#L343 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.5/banner/misc.php#L351 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8.0/banner/misc.php#L424 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8.2/banner/misc.php#L434 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/ultimate-social-media-plus/tags/3.5.7/banner/misc.php#L424 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.7/modules/banner/misc.php#L438 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.8/modules/banner/misc.php#L432 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset/2944041/ultimate-social-media-plus/tags/3.5.8/banner/misc.php?old=2823720&old_path=ultimate-social-media-plus%2Ftags%2F3.5.7%2Fbanner%2Fmisc.php cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?old_path=%2Fcopy-delete-posts%2Ftags%2F1.3.8&old=2923021&new_path=%2Fcopy-delete-posts%2Ftags%2F1.3.9&new=2923021&sfp_email=&sfph_mail= cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2823769%40http-https-remover%2Ftags%2F3.2.3&new=2944114%40http-https-remover%2Ftags%2F3.2.4 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2823770%40feedburner-alternative-and-rss-redirect%2Ftags%2F3.7&new=2944116%40feedburner-alternative-and-rss-redirect%2Ftags%2F3.8#file115 cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/ab7c8926-c762-49b1-bc97-4b7a2f4f97fc?source=cve cve-icon cve-icon
History

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Title Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function
Weaknesses CWE-352

Thu, 03 Apr 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Inisev enhanced Text Widget
CPEs cpe:2.3:a:themecheck:enhanced_text_widget:*:*:*:*:*:wordpress:*:* cpe:2.3:a:inisev:enhanced_text_widget:*:*:*:*:*:wordpress:*:*
Vendors & Products Themecheck
Themecheck enhanced Text Widget
Inisev enhanced Text Widget

Thu, 03 Apr 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Inisev ultimate Posts Widget
CPEs cpe:2.3:a:themecheck:ultimate_posts_widget:*:*:*:*:*:wordpress:*:* cpe:2.3:a:inisev:ultimate_posts_widget:*:*:*:*:*:wordpress:*:*
Vendors & Products Themecheck ultimate Posts Widget
Inisev ultimate Posts Widget

Wed, 05 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Backupbliss Backup Migration Clone
Copy-delete-posts Duplicate Post
Inisev Enhanced Text Widget Redirection Rss Redirect \& Feedburner Alternative Ssl Mixed Content Fix Ultimate Posts Widget
Mypopups Pop-up
Ultimatelysocial Social Media Share Buttons \& Social Sharing Icons
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:14:37.640Z

Reserved: 2023-07-27T16:08:30.895Z

Link: CVE-2023-3977

cve-icon Vulnrichment

Updated: 2024-08-02T07:08:50.857Z

cve-icon NVD

Status : Modified

Published: 2023-07-28T05:15:11.200

Modified: 2026-04-08T19:18:27.717

Link: CVE-2023-3977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses