What the vulnerability does
01Description
Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through <= 1.1.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through <= 1.1.5.
Explanation of Vulnerability in Simple Terms
Button Block for WordPress contains an authorization flaw that allows authenticated users with low privileges to read sensitive data they should not access. The vulnerability affects versions up to 1.1.5. An attacker with a standard user account can retrieve information that should be restricted to administrators or higher-privileged roles.
What an attacker can do
Read sensitive data restricted to higher-privilege users.
Potential impact on your site
Unauthorized disclosure of restricted information to low-privilege user accounts on your site.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities