CVE-2024-23500: WordPress Kadence Blocks plugin <= 3.2.19 - Server Side Request Forgery (SSRF) vulnerability
Published Mar 28, 2024
·Updated
Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through <= 3.2.19.
Affected Software
3 affected components
Kadence WP Gutenberg Blocks<=3.2.19
WordPress Kadence Blocks plugin<=3.2.19
Kadencewp Gutenberg Blocks With Ai Wordpress<3.2.20
Remediation
Information
Update to 3.2.20 or a higher version.
Event History
Mar 28, 2024
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23500?
CVE-2024-23500 has a high severity due to its potential for exploitation through Server-Side Request Forgery.
2
How do I fix CVE-2024-23500?
To fix CVE-2024-23500, update the Kadence WP Gutenberg Blocks plugin to version 3.2.20 or above.
3
Which versions are affected by CVE-2024-23500?
CVE-2024-23500 affects Kadence WP Gutenberg Blocks versions from n/a up to and including 3.2.19.
4
What type of vulnerability is CVE-2024-23500?
CVE-2024-23500 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
5
Is CVE-2024-23500 related to other WordPress plugins?
CVE-2024-23500 specifically affects the Kadence Blocks plugin and does not directly impact other WordPress plugins.