The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the content of private posts and pages.
History

Fri, 07 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 09:30:00 +0000

Type Values Removed Values Added
Description The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the content of private posts and pages.
Title VK Blocks <= 1.94.2.2 - Missing Authorization to Sensitive Information Exposure
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-03-07T09:21:14.540Z

Updated: 2025-03-07T14:13:27.572Z

Reserved: 2025-01-22T19:03:17.354Z

Link: CVE-2024-13635

cve-icon Vulnrichment

Updated: 2025-03-07T14:10:39.265Z

cve-icon NVD

Status : Received

Published: 2025-03-07T10:15:15.840

Modified: 2025-03-07T10:15:15.840

Link: CVE-2024-13635

cve-icon Redhat

No data.