B Slider Gutenberg Slider Block for WordPress Arbitrary Plugin Installation Vulnerability

Vulnerability

A vulnerability allowing arbitrary plugin installation has been identified in the B Slider Gutenberg Slider Block for WordPress, affecting all versions through 1.1.30. The issue arises from inadequate capability checks on the 'activated_plugin' function, enabling authenticated attackers with subscriber-level access or higher to install any plugin on the server. This could potentially lead to remote code execution.

Impact

Exploitation of this vulnerability could allow authenticated users to install malicious plugins, which could be used to execute arbitrary code on the server.

Remediation

Users are advised to update the B Slider Gutenberg Slider Block for WordPress to version 2.0.0 or later.

Added: Aug 12, 2025, 7:23 AM
Updated: Aug 12, 2025, 7:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.9
remediation
7.7
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.