Description
WordPress Plugin Spectra-WordPress Gutenberg Blocks is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change plugin's settings. WordPress Plugin Spectra-WordPress Gutenberg Blocks version 1.14.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.14.8 or latest
References
https://blog.nintechnet.com/wordpress-ultimate-addons-for-gutenberg-plugin-fixed-vulnerability/
https://plugins.svn.wordpress.org/ultimate-addons-for-gutenberg/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Newsletter Cross-Site Scripting (4.6.0)
WordPress Plugin miniOrange Discord Integration Security Bypass (2.1.5)
WordPress Plugin DiveBook Multiple Vulnerabilities (1.1.4)
WordPress Plugin Browsealoud Crypto Mining (1.4)
WordPress Plugin WordPress Survey & Poll-Quiz, Survey and Poll PHP Object Injection (1.5.5)