CVE-2025-2303: Block Logic <= 1.0.8 - Authenticated (Contributor+) Remote Code Execution
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the blocklogicchecklogic function. This is due to the unsafe evaluation of user-controlled input. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2303?
CVE-2025-2303 is classified as a critical vulnerability due to its potential for Remote Code Execution.
How do I fix CVE-2025-2303?
To fix CVE-2025-2303, update the Block Logic – Full Gutenberg Block Display Control plugin to version 1.0.9 or later.
What is affected by CVE-2025-2303?
CVE-2025-2303 affects all versions of the Block Logic – Full Gutenberg Block Display Control plugin up to and including version 1.0.8.
What type of vulnerability is CVE-2025-2303?
CVE-2025-2303 is a Remote Code Execution vulnerability resulting from unsafe evaluation of user input.
Who is the vendor for CVE-2025-2303?
The vendor for CVE-2025-2303 is Block Logic, which develops the Full Gutenberg Block Display Control plugin.