Qubely – Advanced Gutenberg Blocks, c48adbc30436afe8565ce0cf670823f3a52e441d
- CVE, Research URL
- Application
- Published on
- Jun 14, 2022
- Research Description
- Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.1 Qubely <= 1.7.9 - Incorrect Authorization The Qubely plugin for WordPress contains an incorrect authorization weakness that makes it possible for contributor-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to the use of the current_user_can() function checking for the edit_posts permission available to contributors rather than the manage_options permission only available to administrators on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_options AJAX action.
- Affected versions
-
max 1.8.1.
- Status
-
vulnerable