AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-1910

MEDIUM · CVSS 4.3 EPSS 0.52%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-09 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.3. It affects WordPress. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2023-1910
Severity
MEDIUM
CVSS
4.3
EPSS
0.52%
WordPress

Original NVD Description

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to flush the remote template cache. Cached template information can also be accessed via this endpoint but these are not considered sensitive as they are publicly accessible from the developer's site.

Related CVEs

Other vulnerabilities affecting the same vendor(s)