Ad

CVE-2023-3977

MEDIUM CVSS 3.1: 4,3 EPSS 0.61%
Обновлено 8 апреля 2026
Ultimatelysocial
Параметр Значение
CVSS 4,3 (MEDIUM)
Уязвимые версии до 3.8
Устранено в версии 1.2.8
Тип уязвимости CWE-352 (Подделка межсайтовых запросов (CSRF))
Поставщик Ultimatelysocial
Публичный эксплойт Нет

Некоторые плагины для WordPress от Inisev уязвимы к подделке межсайтовых запросов при несанкционированной установке плагинов из-за отсутствия проверки nonce в функции handle_installation, которая вызывается через AJAX-акция inisev_installation в различных версиях. Это позволяет неаутентифицированным злоумышленникам устанавливать плагины из ограниченного списка с помощью поддельного запроса, при условии, что они могут обманом заставить администратора сайта выполнить такое действие, как нажатие на ссылку.

Показать оригинальное описание (EN)

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Нужны права
Не требуются
Права не нужны
Участие пользователя
Требуется
Нужно действие пользователя

Последствия

Конфиденциальность
Нет
Нет утечки данных
Целостность
Низкое
Частичная модификация данных
Доступность
Нет
Нет нарушения работы

Строка CVSS v3.1

Уязвимые продукты 10

Конфигурация От (включительно) До (исключительно)
Backupbliss Backup_Migration
cpe:2.3:a:backupbliss:backup_migration:*:*:*:*:*:wordpress:*:*
— 1.2.8
Backupbliss Clone
cpe:2.3:a:backupbliss:clone:*:*:*:*:*:wordpress:*:*
— 2.3.8
Copy-Delete-Posts Duplicate_Post
cpe:2.3:a:copy-delete-posts:duplicate_post:*:*:*:*:*:wordpress:*:*
— 1.4.0
Inisev Enhanced_Text_Widget
cpe:2.3:a:inisev:enhanced_text_widget:*:*:*:*:*:wordpress:*:*
— 1.5.8
Inisev Redirection
cpe:2.3:a:inisev:redirection:*:*:*:*:*:wordpress:*:*
— 1.1.4
Inisev Rss_Redirect_\&_Feedburner_Alternative
cpe:2.3:a:inisev:rss_redirect_\&_feedburner_alternative:*:*:*:*:*:wordpress:*:*
— 3.8
Inisev Ssl_Mixed_Content_Fix
cpe:2.3:a:inisev:ssl_mixed_content_fix:*:*:*:*:*:wordpress:*:*
— 3.2.4
Inisev Ultimate_Posts_Widget
cpe:2.3:a:inisev:ultimate_posts_widget:*:*:*:*:*:wordpress:*:*
— 2.2.5
Mypopups Pop-Up
cpe:2.3:a:mypopups:pop-up:*:*:*:*:*:wordpress:*:*
— 1.2.0
Ultimatelysocial Social_Media_Share_Buttons_\&_Social_Sharing_Icons
cpe:2.3:a:ultimatelysocial:social_media_share_buttons_\&_social_sharing_icons:*:*:*:*:*:wordpress:*:*
— 3.5.8

Ссылки 23

https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.7/includes/ba…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.8/includes/ba…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.3.8/banner/…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.4.0/banner/…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.6/bann…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.7/bann…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/feedburner-alternative-and-rss-redir…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/http-https-remover/tags/3.2.3/banner…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.1.9/modules/ban…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.2.0/modules/ban…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/redirect-redirection/tags/1.1.3/incl…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.4/ban…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.5/ban…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/ultimate-social-media-plus/tags/3.5.…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.7/mo…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.8/mo…
security@wordfence.com
https://plugins.trac.wordpress.org/changeset/2944041/ultimate-social-media-plus…
security@wordfence.com
https://plugins.trac.wordpress.org/changeset?old_path=%2Fcopy-delete-posts%2Fta…
security@wordfence.com
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&ol…
security@wordfence.com
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&ol…
security@wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/ab7c8926-c762-49b1-bc…
security@wordfence.com