Description
WordPress Plugin Spectra-WordPress Gutenberg Blocks is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change plugin's settings. WordPress Plugin Spectra-WordPress Gutenberg Blocks version 1.14.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.14.8 or latest
References
https://blog.nintechnet.com/wordpress-ultimate-addons-for-gutenberg-plugin-fixed-vulnerability/
https://plugins.svn.wordpress.org/ultimate-addons-for-gutenberg/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WordPress Comments Import & Export Cross-Site Request Forgery (2.1.10)
osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2002-2019)
WordPress Plugin Image Slider Cross-Site Request Forgery (1.1.121)
WordPress Plugin Google Analytics MU Cross-Site Request Forgery (2.3.1)
Microsoft SQL Server CVE-2023-21704 Vulnerability (CVE-2023-21704)