Block Logic <= 1.0.8 - Authenticated (Contributor+) Remote Code Execution
highThe Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the block_logic_check_logic function. This is due to the unsafe evaluation of user-controlled input. This makes it possible for authenticated attackers, with...
- CVSS:
- 8.8
- Affected:
- up to 1.0.8
- Fixed in:
- 2.0.0
- Disclosed:
- Mar 21, 2025