CVE · Medium

CVE-2023-23729 — Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-23729 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.3.2 Missing Authorization Medium 5.4 < 2.3.2 2.3.2 2023-01-23

CVE-2023-23729

The Spectra – WordPress Gutenberg Blocks plugin through version 2.3.1 contains an authorization bypass vulnerability in the forms_recaptcha function that lacks proper capability verification. This flaw allows any authenticated user with contributor access or higher privileges to alter the plugin's Captcha configuration settings. The vulnerability was patched in version 2.3.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.