CVE-2023-2085: Essential Blocks <= 4.0.6 - Missing Authorization via templates
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-2085?
CVE-2023-2085 is a vulnerability found in the Essential Blocks plugin for WordPress.
What is the severity of CVE-2023-2085?
CVE-2023-2085 has a severity rating of medium, with a score of 4.3.
How does CVE-2023-2085 affect the Essential Blocks plugin for WordPress?
CVE-2023-2085 allows subscriber-level attackers to obtain plugin template information.
What is the affected version of the Essential Blocks plugin for WordPress?
The affected version of the Essential Blocks plugin for WordPress is up to, and including, version 4.0.6.
Are there any fixes or patches available for CVE-2023-2085?
Yes, please refer to the official references for fixes and patches for CVE-2023-2085.