WP Clinic
Log in Sign up

CVE · High

CVE-2023-6635 — Gutenberg Block Editor Toolkit – EditorsKit [block-options] < 1.40.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6635 Gutenberg Block Editor Toolkit – EditorsKit [block-options] < 1.40.4 Unrestricted Upload of File with Dangerous Type High 7.2 < 1.40.4 1.40.4 2023-12-16

CVE-2023-6635

Update the WordPress Gutenberg Block Editor Toolkit plugin to the latest available version (at least 1.40.4). István Márton discovered and reported this Arbitrary File Upload vulnerability in WordPress Gutenberg Block Editor Toolkit Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 1.40.4. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.