CVE · Medium

CVE-2025-60094 — Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.19.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-60094 Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.19.0 Missing Authorization Medium 4.3 < 3.19.0 3.19.0 2025-09-26

CVE-2025-60094

Authenticated users with contributor privileges or higher can exploit a security flaw in the Stackable plugin for WordPress, which affects versions through 3.18.1, allowing them to bypass intended access controls. The issue arises from a missing capability check within a specific function. This vulnerability enables attackers to execute unauthorized actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.