First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.5.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thrive Clever Widgets | <=1.5.8 | |
WordPress Enhanced Text Widget | <=1.5.8 |
No patched version is available. No reply from the vendor.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23823 is classified as a missing authorization vulnerability that can lead to unauthorized access.
To fix CVE-2023-23823, update the Clever Widgets Enhanced Text Widget to version 1.5.9 or later.
CVE-2023-23823 affects Clever Widgets Enhanced Text Widget versions up to and including 1.5.8.
Yes, CVE-2023-23823 can affect WordPress sites using the Enhanced Text Widget plugin up to version 1.5.8.
The risks of CVE-2023-23823 include unauthorized access and potential exploitation of incorrectly configured access control settings.