Skip to main content

Vendor archive

artplacer CVEs

Beta · best-effort

3 CVEs tagged to vendor artplacer0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-7269

Published Jul 19, 2024

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-7268

Published Jul 19, 2024

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to dele…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6373

Published Jan 16, 2024

The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1