Description
WordPress Plugin Spectra-WordPress Gutenberg Blocks is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change plugin's settings. WordPress Plugin Spectra-WordPress Gutenberg Blocks version 1.14.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.14.8 or latest
References
https://blog.nintechnet.com/wordpress-ultimate-addons-for-gutenberg-plugin-fixed-vulnerability/
https://plugins.svn.wordpress.org/ultimate-addons-for-gutenberg/trunk/readme.txt
Related Vulnerabilities
Oracle Database Server Other Vulnerability (CVE-2001-0515)
Jenkins Server-Side Request Forgery (SSRF) Vulnerability (CVE-2018-1000067)
Plone arbitrary code execution
WordPress Plugin WP Reroute Email Cross-Site Scripting (1.4.9)
WordPress Plugin GiveWP-Donation and Fundraising Platform PHP Object Injection (2.3.0)