🔐 CVE Alert

CVE-2023-3977

MEDIUM 4.3

Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CWE CWE-352
Vendor inisev
Product redirection
Published Jul 28, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for inisev redirection

Be the first to know when new medium vulnerabilities affecting inisev redirection are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

inisev / Redirection
0 ≤ 1.1.3
inisev / Pop-up
0 ≤ 1.1.9
inisev / BackupBliss – Backup & Migration with Free Cloud Storage
0 ≤ 1.2.7
inisev / Duplicate Post
0 ≤ 1.3.9
cl272 / Enhanced Text Widget
0 ≤ 1.5.7
cl272 / Ultimate Posts Widget
0 ≤ 2.2.4
migrate / Clone
0 ≤ 2.3.7
inisev / Social Media Share Buttons & Social Sharing Icons
0 ≤ 2.8.1
steve85b / SSL Mixed Content Fix
0 ≤ 3.2.3
inisev / Social Share Icons & Social Share Buttons
0 ≤ 3.5.7
s-feeds / RSS Redirect & Feedburner Alternative
0 ≤ 3.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/ab7c8926-c762-49b1-bc97-4b7a2f4f97fc?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/feedburner-alternative-and-rss-redirect/tags/3.7/modules/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8.0/banner/misc.php#L424 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.3.8/banner/misc.php#L426 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.7/modules/banner/misc.php#L438 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.6/banner/misc.php#L339 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.7/includes/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/redirect-redirection/tags/1.1.3/includes/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.4/banner/misc.php#L343 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/http-https-remover/tags/3.2.3/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.1.9/modules/banner/misc.php#L427 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?old_path=%2Fcopy-delete-posts%2Ftags%2F1.3.8&old=2923021&new_path=%2Fcopy-delete-posts%2Ftags%2F1.3.9&new=2923021&sfp_email=&sfph_mail= plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8.2/banner/misc.php#L434 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.4.0/banner/misc.php#L434 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.8/modules/banner/misc.php#L432 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.7/banner/misc.php#L351 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.8/includes/banner/misc.php#L434 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.5/banner/misc.php#L351 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.2.0/modules/banner/misc.php#L432 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-social-media-plus/tags/3.5.7/banner/misc.php#L424 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2823769%40http-https-remover%2Ftags%2F3.2.3&new=2944114%40http-https-remover%2Ftags%2F3.2.4 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2823770%40feedburner-alternative-and-rss-redirect%2Ftags%2F3.7&new=2944116%40feedburner-alternative-and-rss-redirect%2Ftags%2F3.8#file115 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/2944041/ultimate-social-media-plus/tags/3.5.8/banner/misc.php?old=2823720&old_path=ultimate-social-media-plus%2Ftags%2F3.5.7%2Fbanner%2Fmisc.php

Credits

Chloe Chamberland