CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It affects WordPress.
CVE
CVE-2023-6066
Severity
MEDIUM
CVSS
4.3
EPSS
0.39%
WordPress
Original NVD Description
The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.