THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-12449 (MEDIUM 5.4) — The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible f

[NVD] CVE-2025-12449 (MEDIUM 5.4) — The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible f

lownvdPublished 2026-01-07

CVE-2025-12449 CVSS: 5.4 MEDIUM Published: 2026-01-07T12:16:46.710

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible for authenticated attackers, with subscriber level ac

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-12449