PT-2023-16382 · WordPress · Vk Blocks

Ram

+1

·

Published

2023-06-03

·

Updated

2023-06-09

·

CVE-2023-0583

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions VK Blocks plugin for WordPress versions up to, and including, 1.57.0.5
Description The issue concerns improper authorization via the REST update vk blocks options function. This allows authenticated attackers with contributor-level permissions or above to change plugin settings, including default icons.
Recommendations For versions up to, and including, 1.57.0.5, update to a version that contains a fix for this issue to prevent unauthorized changes to plugin settings. As a temporary workaround, consider restricting access to the update vk blocks options function until a patch is available.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-0583

Affected Products

Vk Blocks