Sensitive Information Exposure in GenerateBlocks Plugin for WordPress
CVE-2024-13546
4.3MEDIUM
What is CVE-2024-13546?
The GenerateBlocks plugin for WordPress exposes sensitive information due to a flaw in the 'get_image_description' function. Authenticated attackers, with Contributor-level access or higher, can exploit this vulnerability to gain unauthorized access to sensitive data, including the contents of private, draft, and scheduled posts. This issue affects all versions of GenerateBlocks up to and including 1.9.1, highlighting the need for prompt updates to mitigate potential data breaches.
Affected Version(s)
GenerateBlocks * <= 1.9.1