Kadence Blocks Pro <= 2.3.7 - Authenticated (Contributor+) Information Exposure
mediumThe Kadence Blocks Pro plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.3.7 via the kb-dynamic shortcode. This makes it possible for unauthenticated attackers to extract potentially sensitive data from plugin options.
- CVSS:
- 4.3
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Jun 6, 2024