PT-2026-95270 · WordPress · Magazine Blocks

·

CVE-2026-75017

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress versions prior to 1.8.7
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with contributor-level access or higher can demote published builder templates—including header, footer, front page, single, archive, 404, and search—to draft status. They can then replace these templates with malicious block content rendered across the entire site, facilitating defacement, phishing, and SEO spam. This occurs because the mzb-builder-template post type is registered with capability type='post' and exposed via the REST API, while the mzb template meta key is accessible to any user with edit posts capability, allowing them to trigger the vulnerable save post() function.
Recommendations Update the plugin to a version later than 1.8.6.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75017

Affected Products

Magazine Blocks