Blocksy <= 2.0.97 - Missing Authorization

2025-05-07 00:00
SavPhill (Savphill)

Strategic Overview

Status
Patched in 2.0.98
Affected ThemeBlocksy
Affected Version<= 2.0.97
CVSS2.7Low
CVECVE-2025-47465
View all Blocksy vulnerabilities

Vulnerability Overview

The Blocksy theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_blocksy_notice_button_click AJAX endpoint in versions up to, and including, 2.0.97. This makes it possible for authenticated attackers, with administrator-level access and above, to install plugins. This would only impact sites where administrators have been stripped of their capability to install and activate plugins, which might occur on multi-sites.

Technical Analysis

REMEDIATION: Update to version 2.0.98, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C