CVE-2024-1330

The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:kadencewp:kadence_blocks_pro:*:*:*:*:*:wordpress:*:*

History

28 Jun 2024, 13:30

Type Values Removed Values Added
First Time Kadencewp kadence Blocks Pro
Kadencewp
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
References () https://wpscan.com/vulnerability/1988815b-7a53-4657-9b1c-1f83c9f9ccfd/ - () https://wpscan.com/vulnerability/1988815b-7a53-4657-9b1c-1f83c9f9ccfd/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:kadencewp:kadence_blocks_pro:*:*:*:*:*:wordpress:*:*

27 Jun 2024, 12:47

Type Values Removed Values Added
Summary
  • (es) El complemento de WordPress kadence-blocks-pro anterior a 2.3.8 no impide que los usuarios con al menos el rol de colaborador utilicen algunas de las funcionalidades de su código corto para filtrar opciones arbitrarias de la base de datos.

27 Jun 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 06:15

Updated : 2024-06-28 13:30


NVD link : CVE-2024-1330

Mitre link : CVE-2024-1330

CVE.ORG link : CVE-2024-1330


JSON object : View

Products Affected

kadencewp

  • kadence_blocks_pro