CVE-2024-9234: gutenkit-blocks-addon
## The Exploit An unauthenticated attacker can install and activate arbitrary plugins by sending a single REST API request with no authentication token or capability check. ```http POST /wp-json/gutenkit/v1/install-and-activate-plugin HTT...
Read article →