← WordPress Vulnerabilities
WordPress security by component

Block Logic – Full Gutenberg Block Display Control

Block Logic – Full Gutenberg Block Display Control is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Mar 22, 2025; the highest published CVSS base score is 8.8.

Plugin slug: block-logic

CVE-2025-2303: Block Logic – Full Gutenberg Block Display Control: Code execution

Block Logic – Full Gutenberg Block Display Control is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedMar 22, 2025
Safe version guidanceSee mitigation notes
Published vulnerabilities for block-logic
Safe version
Mar 22, 2025 CVE-2025-2303
Block Logic – Full Gutenberg Block Display Control: Code execution
Block Logic – Full Gutenberg Block Display Control is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending