The Page Builder Gutenberg Blocks WordPress plugin...
Moderate severity
Unreviewed
Published
Jul 23, 2024
to the GitHub Advisory Database
•
Updated May 16, 2025
Description
Published by the National Vulnerability Database
Jul 23, 2024
Published to the GitHub Advisory Database
Jul 23, 2024
Last updated
May 16, 2025
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.
References