CVE · Medium

CVE-2023-2087 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-2083, CVE-2023-2084, CVE-2023-2085, CVE-2023-2086, CVE-2023-2087 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.0.7 Missing Authorization Medium 4.3 < 4.0.7 4.0.7 2023-04-18

CVE-2023-2083, CVE-2023-2084, CVE-2023-2085, CVE-2023-2086, CVE-2023-2087

The Essential Blocks plugin contains a capability check vulnerability in its save function affecting versions up to 4.0.6, allowing attackers with subscriber-level access to modify plugin settings. Although the code includes nonce verification, this check only runs when a nonce is actually supplied, meaning requests without a nonce bypass this protection entirely. The absence of any capability validation means low-privileged users can execute administrative functions they should not have access to.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.