CVE-2023-0583

The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vektor-inc:vk_blocks:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2023-06-03 02:15

Updated : 2023-11-07 04:00


NVD link : CVE-2023-0583

Mitre link : CVE-2023-0583

CVE.ORG link : CVE-2023-0583


JSON object : View

Products Affected

vektor-inc

  • vk_blocks