Qubely – Advanced Gutenberg Blocks <= 1.8.5 - Insufficient Authorization

2023-07-17 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 1.8.6
Affected Version< 1.8.6
CVSS5.3Medium
CVECVE-2021-24916
View all Qubely – Advanced Gutenberg Blocks vulnerabilities

Vulnerability Overview

The Qubely plugin for WordPress is vulnerable to unauthorized arbitrary e-mail sending in versions up to, and including, 1.8.5. This is due to insufficient validation on the presence of a contact form block and validation on the email fields in the qubely_send_form_data() function called via an AJAX action. This makes it possible for unauthenticated attackers to send emails with arbitrary content to arbitrary addresses.

Technical Analysis

REMEDIATION: Update to version 1.8.6, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C