CVE-2025-2568 MEDIUM

CVE-2025-2568: Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary Options Update

Vendor Themehunk
Product Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce
Weakness CWE-862 · Missing authorization
Published April 8, 2025
Last update April 8, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the 'vayu_blocks_get_toggle_switch_values_callback' and 'vayu_blocks_save_toggle_switch_callback' function in versions 1.0.4 to 1.2.1. This makes it possible for unauthenticated attackers to read plugin options and update any option with a key name ending in '_value'.

Explanation of Vulnerability in Simple Terms

02Summary

The Vayu Blocks plugin for WordPress contains a missing authorization flaw that allows unauthenticated attackers to modify site content. An attacker can send a network request to alter data without needing to log in or interact with a user. This affects versions 1.0.4 through 1.2.1. Site owners should update to a version newer than 1.2.1 to restore proper access controls.

What an attacker can do

03Attacker Capabilities

Modify site content or settings without logging in.

Potential impact on your site

04Site Impact

Attackers can alter your site's content, blocks, or WooCommerce data without credentials.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

April 8, 2025 CVE published
April 8, 2025 Record updated

Related vulnerabilities

08Related CVE