Executive brief
aBlocks is a WordPress plugin providing Gutenberg blocks for page building. The plugin fails to properly verify user permissions on multiple AJAX endpoints, allowing authenticated users with basic subscriber-level access to read sensitive configuration data including API keys for email marketing services, block visibility settings, and maintenance mode configuration. This could expose credentials used by website administrators and enable unauthorized modification of website behavior.
Technical details
The vulnerability is a missing capability check in multiple AJAX action handlers within the aBlocks plugin (versions up to 2.4.0). Authenticated attackers with subscriber-level access or above can call AJAX endpoints that lack proper permission validation, allowing them to read plugin settings, block visibility rules, maintenance mode configuration, and third-party API keys for email marketing services. The vulnerable code is located in includes/ajax/settings.php and related files. No special network conditions or user interaction is required beyond initial authentication (any authenticated WordPress user). An attacker can retrieve sensitive API credentials and configuration data, potentially leading to account takeover on third-party services or unauthorized modification of website functionality.
Affected products
- aBlocks aBlocks – WordPress Gutenberg Blocks up to and including 2.4.0
Timeline
- 2026-01-07: disclosed