CVE · High

CVE-2021-24546 — Gutenberg Block Editor Toolkit – EditorsKit [block-options] < 1.31.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24546 Gutenberg Block Editor Toolkit – EditorsKit [block-options] < 1.31.6 Improper Control of Generation of Code ('Code Injection') High 8.8 < 1.31.6 1.31.6 2021-09-13

CVE-2021-24546

The Gutenberg Block Editor Toolkit – EditorsKit plugin in versions before 1.31.6 fails to properly sanitize and validate user input in the Conditional Logic feature of its Custom Visibility settings, which enables contributors and other low-privileged users to inject and execute arbitrary PHP code on the site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.