Security readout for executives and security teams
Plain-English summary
This is a WordPress plugin CSRF issue. If an administrator is logged in and clicks a malicious link, an attacker could cause an affected Inisev-related plugin to install another plugin from a limited allowed list. The impact is limited but operationally relevant because unauthorized plugin installation changes the site.
Executive priority
Treat as a moderate-priority WordPress hygiene issue. It is not reported as actively exploited in the provided sources, but it can let attackers alter a site if an administrator is tricked, so patching and plugin inventory should be scheduled promptly.
Technical view
CVE-2023-3977 is a missing nonce check in the handle_installation function reached through the inisev_installation AJAX action. The CVSS 3.1 score is 4.3, with network access, low complexity, no attacker privileges, required user interaction, and low integrity impact only.
Likely exposure
Exposure is limited to WordPress sites running the affected Inisev-related plugins and versions referenced in the CVE bundle. The provided affected-version data is incomplete and inconsistent, so inventory should verify installed plugin slugs and versions against vendor and WordPress.org guidance.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation. Exploitation requires social engineering a logged-in site administrator into performing an action, such as clicking a link. The attacker is limited to installing plugins from a restricted list, not arbitrary code execution per the cited description.
Researcher notes
Key constraints are user interaction and the limited install list. The bundle references vulnerable and later WordPress.org Trac snapshots, but the normalized affected-version table is not reliable. Avoid assuming arbitrary plugin upload or direct unauthenticated takeover without additional evidence.
Mitigation direction
- Update affected WordPress plugins to vendor-fixed versions where available.
- Remove unused Inisev-related plugins from WordPress sites.
- Restrict administrator sessions to trusted devices and networks where practical.
- Check vendor and WordPress.org plugin pages for exact fixed versions.
- Monitor for unexpected plugin installation or activation events.
Validation and detection
- Inventory WordPress sites for the referenced plugin slugs and versions.
- Confirm whether the handle_installation AJAX path includes nonce validation.
- Review WordPress admin activity for unexpected plugin installation events.
- Compare installed versions against Wordfence and WordPress.org changelog references.
- Confirm no unsupported or abandoned affected plugin remains installed.
Public sources used
- CVE Program
- CVE List V5
- Wordfence Vulnerability Record
- Copy Delete Posts 1.3.8 Trac Reference
- Copy Delete Posts Changeset
- BackupBliss 1.2.7 Trac Reference
- BackupBliss 1.2.8 Trac Reference
- Redirection 1.1.3 Trac Reference
- Pop-up 1.1.9 Trac Reference
- Pop-up 1.2.0 Trac Reference
- Ultimate Social Media Icons 2.8.0 Reference
- Ultimate Social Media Icons 2.8.2 Reference
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-352: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2023-3977 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 4.3 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N2.81.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
4.3MediumVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ab7c8926-c762-49b1-bc97-4b7a2f4f97fc?source=cveCVE reference
- https://plugins.trac.wordpress.org/browser/feedburner-alternative-and-rss-redirect/tags/3.7/modules/banner/misc.php#L427CVE reference
- https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8.0/banner/misc.php#L424CVE reference
- https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.3.8/banner/misc.php#L426CVE reference
- https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.7/modules/banner/misc.php#L438CVE reference
- https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.6/banner/misc.php#L339CVE reference
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.7/includes/banner/misc.php#L427CVE reference
- https://plugins.trac.wordpress.org/browser/redirect-redirection/tags/1.1.3/includes/banner/misc.php#L427CVE reference
- https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.4/banner/misc.php#L343CVE reference
- https://plugins.trac.wordpress.org/browser/http-https-remover/tags/3.2.3/banner/misc.php#L427CVE reference
- https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.1.9/modules/banner/misc.php#L427CVE reference
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fcopy-delete-posts%2Ftags%2F1.3.8&old=2923021&new_path=%2Fcopy-delete-posts%2Ftags%2F1.3.9&new=2923021&sfp_email=&sfph_mail=CVE reference
- https://plugins.trac.wordpress.org/browser/ultimate-social-media-icons/tags/2.8.2/banner/misc.php#L434CVE reference
- https://plugins.trac.wordpress.org/browser/copy-delete-posts/tags/1.4.0/banner/misc.php#L434CVE reference
- https://plugins.trac.wordpress.org/browser/wp-clone-by-wp-academy/tags/2.3.8/modules/banner/misc.php#L432CVE reference
- https://plugins.trac.wordpress.org/browser/enhanced-text-widget/tags/1.5.7/banner/misc.php#L351CVE reference
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.2.8/includes/banner/misc.php#L434CVE reference
- https://plugins.trac.wordpress.org/browser/ultimate-posts-widget/tags/2.2.5/banner/misc.php#L351CVE reference
- https://plugins.trac.wordpress.org/browser/pop-up-pop-up/tags/1.2.0/modules/banner/misc.php#L432CVE reference
- https://plugins.trac.wordpress.org/browser/ultimate-social-media-plus/tags/3.5.7/banner/misc.php#L424CVE reference
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2823769%40http-https-remover%2Ftags%2F3.2.3&new=2944114%40http-https-remover%2Ftags%2F3.2.4CVE reference
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2823770%40feedburner-alternative-and-rss-redirect%2Ftags%2F3.7&new=2944116%40feedburner-alternative-and-rss-redirect%2Ftags%2F3.8#file115CVE reference
- https://plugins.trac.wordpress.org/changeset/2944041/ultimate-social-media-plus/tags/3.5.8/banner/misc.php?old=2823720&old_path=ultimate-social-media-plus%2Ftags%2F3.5.7%2Fbanner%2Fmisc.phpCVE reference
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Cross-Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
