THREAT OPS › Threat News › [NVD] CVE-2025-12449 (MEDIUM 5.4) — The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible f
[NVD] CVE-2025-12449 (MEDIUM 5.4) — The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible f
CVE-2025-12449 CVSS: 5.4 MEDIUM Published: 2026-01-07T12:16:46.710
The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible for authenticated attackers, with subscriber level ac
Indicators of compromise
- CVE-2025-12449cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-12449