CVE-2024-6491: Getwid – Gutenberg Blocks <= 2.0.10 - Missing Authentication to MailChimp API key update
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimpapikeymanage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the MailChimp API key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Getwid – Gutenberg Blocksto a version that resolves this vulnerability.Fixed in 2.0.10 - Configuration
Fix the missing capability check in the mailchimp_api_key_manage function so only users with the required capability can modify the MailChimp API key (Contributor-level access and above should be gated by the correct capability).
Getwid – Gutenberg Blocks (WordPress plugin) mailchimp_api_key_manage capability check = Require appropriate capability check (for Contributor-level and above, not unauthenticated/insufficiently authorized users)
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6491?
The severity of CVE-2024-6491 is considered critical due to the potential for unauthorized data modification.
How do I fix CVE-2024-6491?
To fix CVE-2024-6491, update the Getwid – Gutenberg Blocks plugin to version 2.0.11 or later.
Who is affected by CVE-2024-6491?
CVE-2024-6491 affects all versions of the Getwid – Gutenberg Blocks plugin for WordPress up to and including 2.0.10.
Can CVE-2024-6491 lead to a data breach?
Yes, CVE-2024-6491 can lead to a data breach as it allows authenticated attackers to modify sensitive data.
What should I do if I cannot update to a patched version for CVE-2024-6491?
If you cannot update, you should immediately disable the Getwid – Gutenberg Blocks plugin to mitigate the vulnerability.