Impact
This vulnerability is a Broken Access Control flaw in the Enhanced Blocks – Page Builder Blocks for Gutenberg plugin. It allows a malicious user to bypass the plugin’s access control checks, potentially gaining unauthorized access to its features and configuration settings. The weakness is classified as CWE-862, which means an attacker may perform actions beyond those intended by the application. No additional impacts such as data leakage or code execution are identified in the description, and the CVSS score of 6.5 indicates a moderate severity.
Affected Systems
The flaw affects the Mahmudul Hasan Arif Enhanced Blocks – Page Builder Blocks for Gutenberg plugin, from the earliest released version up through and including 1.4.1. Site administrators running any older or unpatched instance of the plugin are susceptible.
Risk and Exploitability
The CVSS score of 6.5 suggests a noticeable potential risk, but the EPSS score of less than 1% indicates that, at the time of analysis, exploitation attempts are very unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request through the WordPress site that targets the plugin’s admin functions; an attacker with sufficient site credentials, or even a guest visitor if the plugin is misconfigured, may exploit the missing authorization checks to elevate privileges.
OpenCVE Enrichment
EUVD