CVE-2023-45045

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 862

Summary

CVE-2023-45045 is a critical vulnerability affecting the WP Custom Widget area, with versions from n/a to 1.2.5 being impacted. This issue involves a missing authorization control, allowing unauthorized access to the widget area. Hackers can exploit this vulnerability by taking advantage of incorrectly configured access control security levels, potentially leading to significant data breaches or site compromise. Users are strongly encouraged to update their WP Custom Widget plugin to the latest version to mitigate this risk. Failure to address this issue could leave websites vulnerable to attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share