PT-2026-95774 · WordPress · Blockspare

CVE-2026-1242

·

Published

2026-09-19

·

Updated

2026-09-24

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions BlockSpare versions prior to 4.2.7
Description The BlockSpare plugin for WordPress contains an authorization bypass flaw caused by incorrect logic within the permission callback. The issue stems from the use of an AND (&&) operator instead of an OR (||) operator, allowing authenticated users with Subscriber-level access or higher to circumvent authorization checks and create arbitrary posts.
Recommendations Update the plugin to version 4.2.7 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1242

Affected Products

Blockspare