CVE-2023-6295: so-widgets-bundle < 1.51.0 - Admin+ Local File Inclusion
The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6295?
CVE-2023-6295 is considered a high severity vulnerability due to the potential for Local File Inclusion attacks.
How do I fix CVE-2023-6295?
To fix CVE-2023-6295, update the SiteOrigin Widgets Bundle plugin to version 1.51.0 or later.
Who is affected by CVE-2023-6295?
CVE-2023-6295 affects users with the administrator role on Multisite WordPress installations using vulnerable versions of the SiteOrigin Widgets Bundle plugin.
What type of attack is associated with CVE-2023-6295?
CVE-2023-6295 is associated with Local File Inclusion (LFI) attacks.
Is CVE-2023-6295 easy to exploit?
Yes, CVE-2023-6295 can be exploited easily by an authenticated administrator due to the lack of input validation.