CVE-2023-2083, CVE-2023-2084, CVE-2023-2085, CVE-2023-2086, CVE-2023-2087
The Essential Blocks plugin contains a capability check vulnerability in its save function affecting versions up to 4.0.6, allowing attackers with subscriber-level access to modify plugin settings. Although the code includes nonce verification, this check only runs when a nonce is actually supplied, meaning requests without a nonce bypass this protection entirely. The absence of any capability validation means low-privileged users can execute administrative functions they should not have access to.
Based on public CVE data (MITRE/NVD).