cleantalk
Vulnerabilities and Security Researches

Qubely – Advanced Gutenberg Blocks, c63d25742736d7b5b75fb4ef92b6d1a68b90de92

Published on
Jun 06, 2022
Research Description
Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.7.9 Qubely <= 1.7.8 - Missing Authorization The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to missing capability checks on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_options AJAX action that makes it callable via any authenticated user.
Affected versions
max 1.7.9.
Status
vulnerable