WordPress Essential Blocks plugin <= 4.2.0 - Multiple Subscriber+ Broken Access Control vulnerability
CVE-2023-51360
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 December 2024
What is CVE-2023-51360?
A missing authorization vulnerability exists in WPDeveloper Essential Blocks for Gutenberg, which can be exploited due to improperly configured access control levels. This flaw allows unauthorized users to gain elevated privileges and access restricted functions within the plugin, potentially compromising site security. The issue affects all versions of Essential Blocks for Gutenberg from an unspecified initial release through version 4.2.0.
Affected Version(s)
Essential Blocks for Gutenberg <= 4.2.0