CVE-2023-6959: Getwid – Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptchaapikeymanage function in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to add, modify, or delete the 'Recaptcha Site Key' and 'Recaptcha Secret Key' settings.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6959?
CVE-2023-6959 has a medium severity rating due to its potential for unauthorized data modification.
How do I fix CVE-2023-6959?
To fix CVE-2023-6959, update the Getwid – Gutenberg Blocks plugin to version 2.0.4 or later.
Who is affected by CVE-2023-6959?
CVE-2023-6959 affects all versions of the Getwid – Gutenberg Blocks plugin for WordPress up to and including version 2.0.3.
What type of vulnerability is CVE-2023-6959?
CVE-2023-6959 is classified as an authorization vulnerability due to a missing capability check.
Can subscriber-level users exploit CVE-2023-6959?
Yes, authenticated users with subscriber-level access can exploit CVE-2023-6959 to modify data.