Timeline Block WordPress Plugin Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference has been identified in the Timeline Block – Beautiful Timeline Builder for WordPress plugin, affecting all versions up to and including 1.3.3. The issue arises in the tlgb_shortcode() function, where insufficient validation on a user-controlled key allows authenticated attackers with Author-level access and above to access private timeline content by manipulating the id attribute of the 'timeline_block' shortcode.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of private timeline content.

Remediation

Users can update to Timeline Block version 1.3.4, which addresses this vulnerability.

Added: Feb 6, 2026, 3:19 AM
Updated: Feb 6, 2026, 3:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.9
remediation
0.0
relevance
2.6
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.