PT-2026-3342 · WordPress · Page Builder Gutenberg Blocks+1
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress versions up to and including 1.0.1
Description
The Gutenberg Thim Blocks plugin for WordPress is susceptible to unauthorized file access. This is a result of inadequate path validation during the server-side rendering of the thim-blocks/icon block. Authenticated attackers possessing Contributor-level access or higher can potentially read the contents of arbitrary files on the server by manipulating the
iconSVG parameter. This parameter can be used to access sensitive files like wp-config.php.Recommendations
Update Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin to a version later than 1.0.1.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
The Plus Blocks For Block Editor | Gutenberg
Page Builder Gutenberg Blocks