Vulnerability Description
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change the 'vk_font_awesome_version' option to an arbitrary value.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vektor-Inc | Vk Blocks | <= 1.57.0.5 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/vk-blocks/trunk/inc/vk-blocks/font-awPatch
- https://plugins.trac.wordpress.org/changeset/2927751
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b90b7f6c-df7f-48a5-b28Third Party Advisory
- https://plugins.trac.wordpress.org/browser/vk-blocks/trunk/inc/vk-blocks/font-awPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b90b7f6c-df7f-48a5-b28Third Party Advisory
FAQ
What is CVE-2023-0584?
CVE-2023-0584 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with ...
How severe is CVE-2023-0584?
CVE-2023-0584 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0584?
Check the references section above for vendor advisories and patch information. Affected products include: Vektor-Inc Vk Blocks.