CVE-2024-1330: Kadence Blocks Pro < 2.3.8 - Contributor+ Arbitrary Option Access
The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1330?
CVE-2024-1330 is considered a medium severity vulnerability due to the potential for sensitive data exposure by users with the contributor role.
How do I fix CVE-2024-1330?
The fix for CVE-2024-1330 involves updating the Kadence Blocks Pro plugin to version 2.3.8 or later.
Who is affected by CVE-2024-1330?
Users with at least the contributor role in WordPress are affected by CVE-2024-1330 as they can exploit certain shortcodes.
What are the consequences of CVE-2024-1330?
The consequences of CVE-2024-1330 include unauthorized access to and leakage of arbitrary options from the WordPress database.
Is there a patch for CVE-2024-1330?
Yes, the vulnerability is patched in version 2.3.8 of the Kadence Blocks Pro plugin.