CVE-2024-1330: Kadence Blocks Pro < 2.3.8 - Contributor+ Arbitrary Option Access

Description

The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database.

Classification

CVE ID: CVE-2024-1330

Problem Types

CWE-284 Improper Access Control

Affected Products

Vendor: Unknown

Product: kadence-blocks-pro

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.16% (probability of being exploited)

EPSS Percentile: 33.64% (scored less or equal to compared to others)

EPSS Date: 2025-04-11 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-1330
https://wpscan.com/vulnerability/1988815b-7a53-4657-9b1c-1f83c9f9ccfd/

Timeline