CVE · High

CVE-2024-37517 — Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.13.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-37517 Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.13.8 Missing Authorization High 8.8 < 2.13.8 2.13.8 2024-07-05

CVE-2024-37517

The Spectra Legacy – Gutenberg Blocks plugin through version 2.13.7 contains a vulnerability in the generate_ai_content() function that fails to properly verify user capabilities before allowing the action. This flaw allows any authenticated user with contributor-level permissions or higher to generate AI content without proper authorization. The issue was fixed in version 2.13.8.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.