Several plugins that are used on WordPress websites created by Inisev have a security vulnerability that can allow attackers with very limited permissions, such as subscribers, to install certain plugins from Inisev without authorization. This is because of a missing capability check on the handle_installation function, which is called using the inisev_installation AJAX action, in multiple versions. It appears that CVE-2023-38514 is the same vulnerability.