Skip to content
Noroxi

Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager

custom-sidebars · plugin

Known security vulnerabilities for Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager. Find out in seconds which version runs on your site with WP Lens.

2 known vulnerabilities

2 exploitable without logging in · latest Aug 14, 2019

Listed on wordpress.org · latest 3.38 · last updated Aug 16, 2026 · 100K+ installs

wordpress.org status checked on Oct 5, 2026

Vulnerabilities

  • CVE-2017-18511unauthenticated · needs a click

    The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.

    High 8.8
  • CVE-2017-18510unauthenticated · needs a click

    The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.

    High 8.8

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory