B Slider Gutenberg Slider Block for WP Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the B Slider Gutenberg Slider Block for WordPress, affecting versions through 2.0.0. This vulnerability arises from the plugin's 'get_active_plugins' function, which can be exploited by authenticated attackers with subscriber-level access or higher. The flaw allows these attackers to access and extract sensitive data, including information about installed plugins.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, specifically details about installed WordPress plugins, which could be misused for further attacks or to exploit other vulnerabilities.

Reproduction

To reproduce this vulnerability, an authenticated user with subscriber-level access or higher can send a request to the 'get_active_plugins' function via the WordPress admin dashboard. This can be done by using an AJAX request that includes a valid nonce for authentication. The response will contain a list of active plugins, which may include sensitive information that could be exploited.

Remediation

Users are advised to update the B Slider Gutenberg Slider Block for WordPress to version 2.0.1 or later, where this vulnerability has been patched.

Added: Aug 15, 2025, 3:30 AM
Updated: Aug 15, 2025, 3:30 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.3
remediation
7.7
relevance
0.3
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.