Description
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to add, modify, or delete the 'Recaptcha Site Key' and 'Recaptcha Secret Key' settings.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-59155 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to add, modify, or delete the 'Recaptcha Site Key' and 'Recaptcha Secret Key' settings. |
References
History
Wed, 08 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Getwid – Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification |
Mon, 25 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Motopress getwid
|
|
| CPEs | cpe:2.3:a:motopress:getwid:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Motopress getwid - Gutenberg Blocks
|
Motopress getwid
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:01:41.342Z
Reserved: 2023-12-19T19:24:31.193Z
Link: CVE-2023-6959
Updated: 2024-08-02T08:50:06.710Z
Status : Modified
Published: 2024-02-05T22:15:57.767
Modified: 2026-04-08T18:18:45.670
Link: CVE-2023-6959
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD