CVE Database /
CVE-2023-30783
CVE · Medium
CVE-2023-30783 — Sokol: Smart WooCommerce Search [smart-woocommerce-search] < 2.5.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-30783
|
Sokol: Smart WooCommerce Search [smart-woocommerce-search] < 2.5.1 |
Missing Authorization |
Medium
4.3
|
< 2.5.1
|
2.5.1 |
2023-04-18 |
—
|
CVE-2023-30783
The Smart WooCommerce Search plugin for WordPress allows authenticated users with subscriber privileges or higher to duplicate and delete widgets through unprotected AJAX functions in versions 2.5.0 and earlier. The vulnerability stems from inadequate permission validation on the duplicate() and remove() functions, enabling attackers to modify or destroy widget configurations without proper authorization. This flaw was resolved in version 2.5.1.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings