CVE-2022-47594
Last modified
CVE-2022-47594 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 3.8.5.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 3.8.5.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wpdeveloper | Essential Blocks | < 3.8.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-47594?
How severe is CVE-2022-47594?
How do I fix CVE-2022-47594?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-47589Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2022-4759The GigPress WordPress plugin before 2.3.28 does not validat…5.4
- CVE-2022-47590Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2022-47591Reflected Cross-Site Scripting (XSS) vulnerability in Mickae…6.1
- CVE-2022-47592Reflected Cross-Site Scripting (XSS) vulnerability in Dmytri…6.1
- CVE-2022-47593Auth. (subscriber+) SQL Injection (SQLi) vulnerability in Ra…6.5
- CVE-2022-47595Improper Limitation of a Pathname to a Restricted Directory …6.5
- CVE-2022-47596Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2022-47597Exposure of Sensitive Information to an Unauthorized Actor v…7.5
- CVE-2022-47598Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2022-47599Deserialization of Untrusted Data vulnerability in File Mana…7.2
- CVE-2022-4760The OneClick Chat to Order WordPress plugin before 1.0.4.2 d…5.4
Are you affected by CVE-2022-47594?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
