FancyPost WordPress Plugin Missing Authorization Vulnerability in Shortcode Export

Vulnerability

A vulnerability exists in the FancyPost WordPress plugin, specifically in the 'Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor' version 6.0.0 and prior. The issue arises from a lack of proper capability checks in the 'handle_block_shortcode_export()' function, allowing authenticated users with Subscriber-level access and above to export shortcodes without authorization.

Impact

Exploitation of this vulnerability allows for unauthorized data access, specifically the export of shortcodes, by authenticated users with Subscriber-level access or higher.

Remediation

Users can update to version 6.0.1 or a newer patched version to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.9
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.