Intel

AIKIDO-2025-10289

@automattic/newspack-blocks is vulnerable to Weak Password Requirements

Weak Password Requirements Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 6, 2025

15

Low Risk

This Affects:

js@automattic/newspack-blocks
1.33.1 - 4.5.10
Fixed in 4.6.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package do not enforce minimum password length or password complexity requirements when creating an account. This lack of restrictions allows users to create weak, easily guessable passwords, increasing the risk of account compromise through brute force or dictionary attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@automattic/newspack-blocks is vulnerable to Weak Password Requirements in versions 1.33.1 - 4.5.10.

How to fix this

Upgrade the @automattic/newspack-blocks library to the patch version.