CVE Database /
CVE-2023-6964
CVE · Medium
CVE-2023-6964 — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.12
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-6964
|
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.12 |
Server-Side Request Forgery (SSRF) |
Medium
6.4
|
< 3.2.12
|
3.2.12 |
2024-04-09 |
—
|
CVE-2023-6964
The Kadence Blocks plugin for WordPress versions before 3.2.12 contains a server-side request forgery vulnerability that was discovered by Lucio Sá. An attacker could exploit this flaw to force the affected website to make HTTP requests to arbitrary domains controlled by the attacker, potentially exposing sensitive data from internal services or other systems accessible from the web server. The vulnerability has been resolved in version 3.2.12 and users should update immediately.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings