Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.5epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Unknown · Gutenberg Essential Blockspublic PoCs found — 1
cve_referencewpscan.com/vulnerability/ab60ebee-c8b5-4bba-8138-2083ca14546a/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.