Description
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the block_logic_check_logic function. This is due to the unsafe evaluation of user-controlled input. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version
Timeline
| 2025-03-11: | Discovered |
| 2025-03-21: | Disclosed |
Credits
Oliver Campion
References
www.wordfence.com/...-3f4e-4457-a33c-eede51c4b4d1?source=cve
plugins.trac.wordpress.org/...gic/tags/1.0.8/block-logic.php
plugins.trac.wordpress.org/changeset/3430763/