CVE-2023-2086: Essential Blocks <= 4.0.6 - Missing Authorization via template_count
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templatecount function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2086?
The severity of CVE-2023-2086 is medium with a CVSS score of 4.3.
How does CVE-2023-2086 affect the Essential Blocks plugin for WordPress?
CVE-2023-2086 affects the Essential Blocks plugin for WordPress versions up to and including 4.0.6.
What is the vulnerability description of CVE-2023-2086?
CVE-2023-2086 is a vulnerability in the Essential Blocks plugin for WordPress that allows unauthorized use of functionality due to a missing capability check on the template_count function, allowing subscriber-level attackers to obtain plugin template information.
How can I fix CVE-2023-2086?
To fix CVE-2023-2086, update the Essential Blocks plugin for WordPress to version 4.0.7 or higher.
Where can I find more information about CVE-2023-2086?
You can find more information about CVE-2023-2086 on the official WordPress plugin page and the Wordfence threat intelligence website.