LiveActive security incident?Get immediate response
CVE Record

CVE-2023-3977: Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

MediumCVSS 4.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a WordPress plugin CSRF issue. If an administrator is logged in and clicks a malicious link, an attacker could cause an affected Inisev-related plugin to install another plugin from a limited allowed list. The impact is limited but operationally relevant because unauthorized plugin installation changes the site.

Executive priority

Treat as a moderate-priority WordPress hygiene issue. It is not reported as actively exploited in the provided sources, but it can let attackers alter a site if an administrator is tricked, so patching and plugin inventory should be scheduled promptly.

Technical view

CVE-2023-3977 is a missing nonce check in the handle_installation function reached through the inisev_installation AJAX action. The CVSS 3.1 score is 4.3, with network access, low complexity, no attacker privileges, required user interaction, and low integrity impact only.

Likely exposure

Exposure is limited to WordPress sites running the affected Inisev-related plugins and versions referenced in the CVE bundle. The provided affected-version data is incomplete and inconsistent, so inventory should verify installed plugin slugs and versions against vendor and WordPress.org guidance.

Exploitation context

The source bundle does not show CISA KEV listing or active exploitation. Exploitation requires social engineering a logged-in site administrator into performing an action, such as clicking a link. The attacker is limited to installing plugins from a restricted list, not arbitrary code execution per the cited description.

Researcher notes

Key constraints are user interaction and the limited install list. The bundle references vulnerable and later WordPress.org Trac snapshots, but the normalized affected-version table is not reliable. Avoid assuming arbitrary plugin upload or direct unauthenticated takeover without additional evidence.

Mitigation direction

  • Update affected WordPress plugins to vendor-fixed versions where available.
  • Remove unused Inisev-related plugins from WordPress sites.
  • Restrict administrator sessions to trusted devices and networks where practical.
  • Check vendor and WordPress.org plugin pages for exact fixed versions.
  • Monitor for unexpected plugin installation or activation events.

Validation and detection

  • Inventory WordPress sites for the referenced plugin slugs and versions.
  • Confirm whether the handle_installation AJAX path includes nonce validation.
  • Review WordPress admin activity for unexpected plugin installation events.
  • Compare installed versions against Wordfence and WordPress.org changelog references.
  • Confirm no unsupported or abandoned affected plugin remains installed.
Prepared
Confidence
medium
Sources
12

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-352: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2023-3977 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
4.3 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
24Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
4.3CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N2.81.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

4.3Medium
CVSS 3.1 vector shape for CVE-2023-3977Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
inisevRedirection0unaffected
inisevPop-up0unaffected
inisevBackupBliss – Backup & Migration with Free Cloud Storage0unaffected
inisevDuplicate Post0unaffected
cl272Enhanced Text Widget0unaffected
cl272Ultimate Posts Widget0unaffected
migrateClone0unaffected
inisevSocial Media Share Buttons & Social Sharing Icons0unaffected
steve85bSSL Mixed Content Fix0unaffected
inisevSocial Share Icons & Social Share Buttons0unaffected
s-feedsRSS Redirect & Feedburner Alternative0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-352 · source CWE mapping

Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.