Description
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in versions less than, or equal to, 2.0.0 via the get_active_plugins function. This makes it possible for authenticated attackers, with subscriber-level access and above to extract sensitive data including installed plugin information.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
*
Timeline
2025-07-28: | Discovered |
2025-08-06: | Vendor Notified |
2025-08-14: | Disclosed |
Credits
wesley
References
www.wordfence.com/...-cf49-4a5c-a187-0f09ac53c337?source=cve
plugins.trac.wordpress.org/...ider/tags/1.1.30/adminMenu.php
plugins.trac.wordpress.org/...b-slider&sfp_email=&sfph_mail=