What the vulnerability does
01Description
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg.This issue affects Essential Blocks for Gutenberg: from n/a through 4.4.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg.This issue affects Essential Blocks for Gutenberg: from n/a through 4.4.9.
Explanation of Vulnerability in Simple Terms
Essential Blocks for Gutenberg versions up to 4.4.9 lack proper authorization checks on certain functions. An authenticated user with low privileges can read sensitive data they should not have access to. The vulnerability does not allow data modification or site unavailability. Update to a version newer than 4.4.9.
What an attacker can do
Read sensitive data from the site that should be restricted to higher-privilege users.
Potential impact on your site
Unauthorized users can access confidential information stored in the plugin, such as private content or settings.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities