The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change the 'vk_font_awesome_version' option to an arbitrary value.
CVE ID: CVE-2023-0584
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.3
Vendor: vektor-inc
Product: VK Blocks
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 30.58% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)