CVE · Medium

CVE-2023-30783 — Sokol: Smart WooCommerce Search [smart-woocommerce-search] < 2.5.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-30783 Sokol: Smart WooCommerce Search [smart-woocommerce-search] < 2.5.1 Missing Authorization Medium 4.3 < 2.5.1 2.5.1 2023-04-18

CVE-2023-30783

The Smart WooCommerce Search plugin for WordPress allows authenticated users with subscriber privileges or higher to duplicate and delete widgets through unprotected AJAX functions in versions 2.5.0 and earlier. The vulnerability stems from inadequate permission validation on the duplicate() and remove() functions, enabling attackers to modify or destroy widget configurations without proper authorization. This flaw was resolved in version 2.5.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.