Description
WordPress Plugin Spectra-WordPress Gutenberg Blocks is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change plugin's settings. WordPress Plugin Spectra-WordPress Gutenberg Blocks version 1.14.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.14.8 or latest
References
https://blog.nintechnet.com/wordpress-ultimate-addons-for-gutenberg-plugin-fixed-vulnerability/
https://plugins.svn.wordpress.org/ultimate-addons-for-gutenberg/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WordPress Poll Multiple SQL Injection Vulnerabilities (33.5)
WordPress Plugin Subscribe2 Cross-Site Scripting (10.15)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-30153)
WordPress Plugin Attachment File Icons (AF Icons) Cross-Site Request Forgery (1.3)
XOOPS Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-4851)