Qubely – Advanced Gutenberg Blocks, c63d25742736d7b5b75fb4ef92b6d1a68b90de92
- CVE, Research URL
- Application
- Published on
- Jun 06, 2022
- Research Description
- Qubely – Advanced Gutenberg Blocks [qubely] < 1.7.9 Qubely <= 1.7.8 - Missing Authorization The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to missing capability checks on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_options AJAX action that makes it callable via any authenticated user.
- Affected versions
-
max 1.7.9.
- Status
-
vulnerable