cleantalk
Vulnerabilities and Security Researches

Qubely – Advanced Gutenberg Blocks, c48adbc30436afe8565ce0cf670823f3a52e441d

Published on
Jun 14, 2022
Research Description
Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.1 Qubely <= 1.7.9 - Incorrect Authorization The Qubely plugin for WordPress contains an incorrect authorization weakness that makes it possible for contributor-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to the use of the current_user_can() function checking for the edit_posts permission available to contributors rather than the manage_options permission only available to administrators on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_options AJAX action.
Affected versions
max 1.8.1.
Status
vulnerable