Description
WordPress Plugin Global Content Blocks is prone to multiple security vulnerabilities, including a remote PHP code execution vulnerability and multiple information disclosure vulnerabilities. Successful exploits of these issues may allow remote attackers to execute arbitrary malicious PHP code in the context of the application or obtain potentially sensitive information. WordPress Plugin Global Content Blocks version 1.5.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.2 or latest
References
Related Vulnerabilities
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-31548)
WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder For WordPress CSV Injection (1.4.7)
Python Integer Overflow or Wraparound Vulnerability (CVE-2017-1000158)
WordPress Plugin Contact Form for WordPress-Ultimate Form Builder Lite Cross-Site Scripting (1.3.3)
Python Inadequate Encryption Strength Vulnerability (CVE-2014-0224)