High severity8.8NVD Advisory· Published Mar 22, 2025· Updated Jun 17, 2026
CVE-2025-2303
CVE-2025-2303
Description
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the block_logic_check_logic function. This is due to the unsafe evaluation of user-controlled input. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=1.0.8+ 1 more
- (no CPE)range: <=1.0.8
- (no CPE)range: <=1.0.8
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.