PT-2026-95270 · WordPress · Magazine Blocks
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress versions prior to 1.8.7
Description
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with contributor-level access or higher can demote published builder templates—including header, footer, front page, single, archive, 404, and search—to draft status. They can then replace these templates with malicious block content rendered across the entire site, facilitating defacement, phishing, and SEO spam. This occurs because the
mzb-builder-template post type is registered with capability type='post' and exposed via the REST API, while the mzb template meta key is accessible to any user with edit posts capability, allowing them to trigger the vulnerable save post() function.Recommendations
Update the plugin to a version later than 1.8.6.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magazine Blocks