B Slider Gutenberg Slider Block for WordPress Arbitrary Plugin Installation Vulnerability
Vulnerability
A vulnerability allowing arbitrary plugin installation has been identified in the B Slider Gutenberg Slider Block for WordPress, affecting all versions through 1.1.30. The issue arises from inadequate capability checks on the 'activated_plugin' function, enabling authenticated attackers with subscriber-level access or higher to install any plugin on the server. This could potentially lead to remote code execution.
Impact
Exploitation of this vulnerability could allow authenticated users to install malicious plugins, which could be used to execute arbitrary code on the server.
Remediation
Users are advised to update the B Slider Gutenberg Slider Block for WordPress to version 2.0.0 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
