🔐 CVE Alert

CVE-2023-0958

MEDIUM 4.3

Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to install select plugins from Inisev on vulnerable sites. CVE-2023-38514 appears to be a duplicate of this vulnerability.

CWE CWE-862
Vendor inisev
Product redirection
Published Jul 28, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for inisev redirection

Be the first to know when new medium vulnerabilities affecting inisev redirection are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

inisev / Redirection
0 ≤ 1.1.3
inisev / Pop-up
0 ≤ 1.1.9
inisev / BackupBliss – Backup & Migration with Free Cloud Storage
0 ≤ 1.2.7
inisev / Duplicate Post
0 ≤ 1.3.9
cl272 / Enhanced Text Widget
0 ≤ 1.5.7
cl272 / Ultimate Posts Widget
0 ≤ 2.2.4
migrate / Clone
0 ≤ 2.3.7
inisev / Social Media Share Buttons & Social Sharing Icons
0 ≤ 2.8.1
steve85b / SSL Mixed Content Fix
0 ≤ 3.2.3
inisev / Social Share Icons & Social Share Buttons
0 ≤ 3.5.7
s-feeds / RSS Redirect & Feedburner Alternative
0 ≤ 3.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/cf7bdd0e-f3b3-4be5-8a30-2c6d9cb783a3?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/feedburner-alternative-and-rss-redirect/tags/3.7/modules/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8.0/banner/misc.php#L424 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.3.8/banner/misc.php#L426 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.7/modules/banner/misc.php#L438 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.6/banner/misc.php#L339 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.7/includes/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/redirect-redirection/tags/1.1.3/includes/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.4/banner/misc.php#L343 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/http-https-remover/tags/3.2.3/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.1.9/modules/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?old_path=%2Fcopy-delete-posts%2Ftags%2F1.3.8&old=2923021&new_path=%2Fcopy-delete-posts%2Ftags%2F1.3.9&new=2923021&sfp_email=&sfph_mail= plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8.2/banner/misc.php#L434 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.4.0/banner/misc.php#L434 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.8/modules/banner/misc.php#L432 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.7/banner/misc.php#L351 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.8/includes/banner/misc.php#L434 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.5/banner/misc.php#L351 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.2.0/modules/banner/misc.php#L432 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-social-media-plus/tags/3.5.7/banner/misc.php#L424 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2823769%40http-https-remover%2Ftags%2F3.2.3&new=2944114%40http-https-remover%2Ftags%2F3.2.4 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2823770%40feedburner-alternative-and-rss-redirect%2Ftags%2F3.7&new=2944116%40feedburner-alternative-and-rss-redirect%2Ftags%2F3.8#file115 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/2944041/ultimate-social-media-plus/tags/3.5.8/banner/misc.php?old=2823720&old_path=ultimate-social-media-plus%2Ftags%2F3.5.7%2Fbanner%2Fmisc.php

Credits

Chloe Chamberland