CVE · Medium

CVE-2023-36676 — Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-36676 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.6.7 Missing Authorization Medium 5.4 < 2.6.7 2.6.7 2023-07-14

CVE-2023-36676

The Spectra Legacy Gutenberg Blocks plugin in versions up to 2.6.6 allows authenticated users with Contributor-level permissions and higher to execute unauthorized actions because a critical function lacks proper capability validation. This vulnerability enables attackers to bypass intended access restrictions and perform operations they should not be able to carry out. The issue was addressed in version 2.6.7 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.