Spectra – WordPress Gutenberg Blocks <= 2.3.1 - HTML Injection in Emails
2023-01-23 00:00
Dave JongStrategic Overview
StatusPatched in 2.3.2
Affected PluginSpectra Legacy – Gutenberg Blocks
Affected Version
<= 2.3.1CVSS6.5Medium
CVE
CVE-2023-23735Vulnerability Overview
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to HTML injection via Email in versions up to, and including, 2.3.1. This is due to insufficient input validation and output escaping of content being sent via email. This makes it possible for unauthenticated attackers to send emails to unsuspecting victims with content containing HTML.
Technical Analysis
REMEDIATION: Update to version 2.3.2, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C