CVE-2025-24751: WordPress CoBlocks plugin <= 3.1.13 - Broken Access Control vulnerability
Published Jan 24, 2025
·Updated
Missing Authorization vulnerability in GoDaddy CoBlocks coblocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoBlocks: from n/a through <= 3.1.13.
Affected Software
1 affected component
GoDaddy CoBlocks<=3.1.13
Remediation
Information
Update the WordPress CoBlocks wordpress plugin to the latest available version (at least 3.1.14).
Event History
Jan 24, 2025
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24751?
CVE-2025-24751 is classified as a missing authorization vulnerability that can lead to unauthorized access.
2
How do I fix CVE-2025-24751?
To fix CVE-2025-24751, update GoDaddy CoBlocks to version 3.1.14 or later.
3
What versions of CoBlocks are affected by CVE-2025-24751?
CVE-2025-24751 affects CoBlocks versions up to and including 3.1.13.
4
What is the impact of CVE-2025-24751?
The impact of CVE-2025-24751 is the exploitation of incorrectly configured access control security levels, potentially allowing unauthorized actions.
5
Who is the vendor responsible for CVE-2025-24751?
The vendor responsible for CVE-2025-24751 is GoDaddy, associated with the CoBlocks plugin.