CVE · Medium

CVE-2023-2084 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-2084 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7 Missing Authorization Medium 4.3 < 4.0.7 4.0.7 2023-04-18

CVE-2023-2084

The Essential Blocks plugin for WordPress contains a vulnerability in versions 4.0.6 and earlier where the get function lacks proper capability verification, allowing users with subscriber-level permissions to access plugin settings. Although the code includes nonce validation, this check only runs when a nonce is actually supplied, meaning attackers can bypass it entirely by omitting the nonce parameter since no capability restrictions exist on the function itself.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.