What the vulnerability does
01Description
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Explanation of Vulnerability in Simple Terms
Kadence Blocks versions up to 3.7.8 leak sensitive information in outbound data. An authenticated user with low privileges can trigger the plugin to expose data in network communications. The exposure is limited to confidentiality; site functionality and data integrity are not affected. Update to a version newer than 3.7.8.
What an attacker can do
View sensitive information transmitted by the plugin in network communications.
Potential impact on your site
Sensitive data may be exposed to users with basic site access; review plugin communications for data leakage.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities