Lucene search

K
wpvulndbScott Kingsley ClarkWPVDB-ID:1988815B-7A53-4657-9B1C-1F83C9F9CCFD
HistoryJun 06, 2024 - 12:00 a.m.

Kadence Blocks Pro < 2.3.8 - Contributor+ Arbitrary Option Access

2024-06-0600:00:00
Scott Kingsley Clark
wpscan.com
3
kadence blocks pro
contributor
arbitrary option access
database
shortcode
security vulnerability
poc
update

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Description The plugin does not prevent users with at least the contributor role using some of its shortcode’s functionalities to leak arbitrary options from the database.

PoC

1. ADMIN: Install Kadence Blocks Pro 2. CONTRIBUTOR: Add shortcode to any post and specify/guess the option name and save 3. CONTRIBUTOR: Preview the post and see option you shouldn’t have access to Example shortcode: [kb-dynamic para="kb_custom_input" custom="active_plugins" field="site|custom_setting"]

CPENameOperatorVersion
eq2.3.8

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Related for WPVDB-ID:1988815B-7A53-4657-9B1C-1F83C9F9CCFD