Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to install select plugins from Inisev on vulnerable sites. CVE-2023-38514 appears to be a duplicate of this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Backup Backup Plugin | backup-backup-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Copy Delete Posts Plugin | copy-delete-posts-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Enhanced Text Widget Plugin | enhanced-text-widget-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Feedburner Alternative And Rss Redirect Plugin | feedburner-alternative-and-rss-redirect-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Http Https Remover Plugin | http-https-remover-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Pop Up Pop Up Plugin | pop-up-pop-up-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Redirect Redirection Plugin | redirect-redirection-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Ultimate Posts Widget Plugin | ultimate-posts-widget-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Ultimate Social Media Icons Plugin | ultimate-social-media-icons-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Ultimate Social Media Plus Plugin | ultimate-social-media-plus-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 | |
| Wp Clone By Wp Academy Plugin | wp-clone-by-wp-academy-plugin-cve-2023-0958 | May 15, 2025 | Jul 27, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub