Lucene search

K
wpvulndbWpvulndbWPVDB-ID:3A3485B0-F928-4A1E-8FC8-E090E7880337
HistoryJun 02, 2023 - 12:00 a.m.

VK Blocks < 1.58.0.0 - Contributor+ Settings Update via REST API

2023-06-0200:00:00
wpscan.com
6
vk blocks
rest api
authorization
contributor role
vk_font_awesome_version
software security

0.001 Low

EPSS

Percentile

40.6%

The plugin uses improper authorization for the REST API vk-blocks/v1/options/vk_font_awesome_version, allowing users with a role as low as contributor to change the vk_font_awesome_version option to an arbitrary value.

CPENameOperatorVersion
vk-blockslt1.58.0.0

0.001 Low

EPSS

Percentile

40.6%

Related for WPVDB-ID:3A3485B0-F928-4A1E-8FC8-E090E7880337