CVE · Medium

CVE-2023-2085 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-2085 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7 Missing Authorization Medium 4.3 < 4.0.7 4.0.7 2023-04-18

CVE-2023-2085

The Essential Blocks plugin for WordPress before version 4.0.7 contains a capability check vulnerability in its templates function that allows attackers with subscriber-level access to retrieve plugin template data. The vulnerability exists because the nonce verification is only performed when a nonce is actually supplied, meaning requests without a nonce bypass the security check entirely. Additionally, the absence of a proper capability restriction enables lower-privileged users to access functionality they should not be permitted to use.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.