CVE-2020-36702: Spectra – WordPress Gutenberg Blocks <= 1.14.7 - Missing Authorization
Published Jun 7, 2023
·Updated
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.
Affected Software
1 affected component
Brainstormforce Spectra Wordpress<=1.14.7
Event History
Jun 7, 2023
CVE Published
via MITRE·01:51 AM
Data Sourced
via MITRE·01:51 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of the Ultimate Addons for Gutenberg plugin vulnerability?
The vulnerability ID is CVE-2020-36702.
2
What is the severity of CVE-2020-36702?
The severity of CVE-2020-36702 is medium with a severity value of 4.3.
3
Which version of the Ultimate Addons for Gutenberg plugin is affected by CVE-2020-36702?
Versions up to and including 1.14.7 of the Ultimate Addons for Gutenberg plugin are affected by CVE-2020-36702.
4
What is the impact of the Ultimate Addons for Gutenberg plugin vulnerability?
Authenticated attackers with subscriber+ roles can exploit this vulnerability to update plugin settings.
5
Are there any fixes available for CVE-2020-36702?
Yes, a fix for CVE-2020-36702 has been released for the Ultimate Addons for Gutenberg plugin.