CVE-2023-23729: WordPress Spectra – WordPress Gutenberg Blocks plugin <= 2.3.0 - Contributor+ reCAPTCHA Settings Change Vulnerability
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.
Other sources
Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.3.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23729?
CVE-2023-23729 is classified as a missing authorization vulnerability that can lead to improperly configured access controls.
How do I fix CVE-2023-23729?
To fix CVE-2023-23729, upgrade the Brainstorm Force Spectra plugin to version 2.3.1 or later.
What versions of Spectra are affected by CVE-2023-23729?
CVE-2023-23729 affects all versions of Spectra from n/a through 2.3.0.
What kind of systems are impacted by CVE-2023-23729?
CVE-2023-23729 impacts WordPress installations using the Spectra plugin with incorrect access control configurations.
Who is responsible for patching CVE-2023-23729?
The responsibility for patching CVE-2023-23729 falls on the users of the Brainstorm Force Spectra plugin to update to the latest version.