CVE-2023-51359: WordPress Essential Blocks plugin <= 4.2.0 - Multiple Contributor+ Broken Access Control vulnerability
Published Dec 9, 2024
·Updated
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through <= 4.2.0.
Affected Software
3 affected components
WPDeveloper Essential Blocks Wordpress<4.2.1
WPDeveloper Essential Blocks for Gutenberg<=4.2.0
WordPress Essential Blocks<=4.2.0
Remediation
Information
Update the WordPress Essential Blocks for Gutenberg plugin to the latest available version (at least 4.2.1).
Event History
Dec 9, 2024
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-51359?
The severity of CVE-2023-51359 is considered high due to its potential impact on access control.
2
How do I fix CVE-2023-51359?
To fix CVE-2023-51359, update Essential Blocks for Gutenberg to version 4.2.1 or later.
3
What versions of Essential Blocks for Gutenberg are affected by CVE-2023-51359?
CVE-2023-51359 affects versions from n/a through 4.2.0 of Essential Blocks for Gutenberg.
4
What type of vulnerability is CVE-2023-51359?
CVE-2023-51359 is a missing authorization vulnerability resulting from incorrectly configured access control levels.
5
Who is the vendor of the affected software in CVE-2023-51359?
The vendor of the affected software in CVE-2023-51359 is WPDeveloper.