CVE-2023-1807: Elementor Addons, Widgets and Enhancements – Stax <= 1.4.3 - Cross-Site Request Forgery via toggle_widget
The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.3. This is due to missing or incorrect nonce validation on the togglewidget function. This makes it possible for unauthenticated attackers to enable or disable Elementor widgets via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1807?
CVE-2023-1807 has been classified as a medium severity vulnerability due to potential unauthorized actions by unauthenticated attackers.
How do I fix CVE-2023-1807?
To fix CVE-2023-1807, update the Stax plugin to version 1.4.4 or later which includes the necessary nonce validation.
Who is affected by CVE-2023-1807?
CVE-2023-1807 affects all users of the Stax plugin for WordPress running versions up to 1.4.3.
What type of vulnerability is CVE-2023-1807?
CVE-2023-1807 is a Cross-Site Request Forgery vulnerability that could be exploited to perform unauthorized actions.
Can CVE-2023-1807 be exploited remotely?
Yes, CVE-2023-1807 can be exploited remotely by unauthenticated attackers without access to the WordPress admin area.