WP Clinic
Log in Sign up

CVE · High

CVE-2021-24546 — Gutenberg Block Editor Toolkit – EditorsKit [block-options] < 1.31.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24546 Gutenberg Block Editor Toolkit – EditorsKit [block-options] < 1.31.6 Improper Control of Generation of Code ('Code Injection') High 8.8 < 1.31.6 1.31.6 2021-09-13

CVE-2021-24546

The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.