Spectra – WordPress Gutenberg Blocks <= 2.3.1 - HTML Injection in Emails

2023-01-23 00:00
Dave Jong

Strategic Overview

Status
Patched in 2.3.2
Affected Version<= 2.3.1
CVSS6.5Medium
CVECVE-2023-23735
View all Spectra Legacy – Gutenberg Blocks vulnerabilities

Vulnerability Overview

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to HTML injection via Email in versions up to, and including, 2.3.1. This is due to insufficient input validation and output escaping of content being sent via email. This makes it possible for unauthenticated attackers to send emails to unsuspecting victims with content containing HTML.

Technical Analysis

REMEDIATION: Update to version 2.3.2, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C