CVE · Medium

CVE-2023-2086 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-2086 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7 Missing Authorization Medium 4.3 < 4.0.7 4.0.7 2023-04-18

CVE-2023-2086

The Essential Blocks plugin contains a capability check vulnerability in its template_count function affecting versions up to 4.0.6, allowing attackers with subscriber-level access to retrieve plugin template data. Although the code includes nonce verification, this check only activates when a nonce is actually supplied, meaning requests without a nonce bypass the verification entirely. The absence of any capability restrictions means any authenticated user can exploit this flaw to access sensitive template information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.