CVE-2025-2303

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 22, 2025
CWE ID 94

Summary

CVE-2025-2303 is a Remote Code Execution vulnerability affecting the Block Logic – Full Gutenberg Block Display Control plugin for WordPress. Versions up to 1.0.8 are vulnerable. The issue lies within the block_logic_check_logic function, which unsafely evaluates user-controlled input. This weakness allows authenticated attackers with Contributor-level access or higher to execute code on the server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share