First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.6.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thrive Clever Widgets | <=1.6.3 | |
WordPress Enhanced Text Widget | <=1.6.3 |
No patched version is available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49192 is classified as a missing authorization vulnerability that poses a significant risk due to incorrectly configured access control security levels.
To fix CVE-2023-49192, update the Enhanced Text Widget to version 1.6.4 or higher, which addresses the access control issues.
CVE-2023-49192 affects versions of the Enhanced Text Widget from n/a through 1.6.3.
Exploiting CVE-2023-49192 may allow unauthorized users to gain access to restricted functionalities within the Enhanced Text Widget.
Yes, CVE-2023-49192 can potentially lead to unauthorized access to sensitive data if not mitigated.