cve/2021/CVE-2021-24546.md
2024-06-18 02:51:15 +02:00

895 B
Raw Blame History

CVE-2021-24546

Description

The Gutenberg Block Editor Toolkit EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code

POC

Reference

Github