Access Control Flaw in Enhanced Blocks – Page Builder for Gutenberg by Mahmudul Hasan Arif
CVE-2025-50034
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 June 2025
What is CVE-2025-50034?
A missing authorization vulnerability exists in the Enhanced Blocks – Page Builder Blocks for Gutenberg plugin developed by Mahmudul Hasan Arif. This flaw allows unauthorized access due to improperly configured access control security levels. Attackers can exploit this weakness to gain access to restricted functionalities of the plugin, ultimately compromising the site's security. This vulnerability affects all versions from n/a to 1.4.1, making it essential for users to assess their installations and apply updates or patches as necessary.
Affected Version(s)
Enhanced Blocks – Page Builder Blocks for Gutenberg <= 1.4.1