Access violation vulnerability in Newspack Blocks 3.0.8

The plugin called Newspack Blocks for WordPress can be accessed by unauthorized individuals and their data can be viewed. This is because the plugin does not have a check for certain abilities on the api_get_all_authors and get_authors REST API endpoints. This means that people who are logged in and have contributor-level access or higher can see information about the authors.

Detected in:

Newspack Blocks fixed vulnerable versions: >= * <= 3.0.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.