Vulnerability Description
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vektor-Inc | Vk Blocks | <= 1.57.0.5 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/vk-blocks/trunk/inc/vk-blocks/App/ResPatch
- https://plugins.trac.wordpress.org/changeset/2921566/vk-blocks/tags/1.57.1.0/inc
- https://www.wordfence.com/threat-intel/vulnerabilities/id/12a94f5b-bc30-4a65-b39Third Party Advisory
- https://plugins.trac.wordpress.org/browser/vk-blocks/trunk/inc/vk-blocks/App/ResPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/12a94f5b-bc30-4a65-b39Third Party Advisory
FAQ
What is CVE-2023-0583?
CVE-2023-0583 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attack...
How severe is CVE-2023-0583?
CVE-2023-0583 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0583?
Check the references section above for vendor advisories and patch information. Affected products include: Vektor-Inc Vk Blocks.