Executive brief
B Blocks, a WordPress plugin used for enhancing page building capabilities, contains a security flaw that allows users with low-level 'Contributor' accounts to gain unauthorized administrative access. By exploiting this vulnerability, an attacker could take full control of the website, potentially leading to data theft, site defacement, or the installation of malicious software. This poses a significant risk to site integrity and operational continuity.
Technical details
The B Blocks plugin for WordPress (versions up to and including 2.0.31) is vulnerable to privilege escalation due to incorrect privilege assignment (CWE-266). An authenticated attacker with 'Contributor' level permissions can exploit this flaw via the network without user interaction to escalate their privileges. Successful exploitation allows the attacker to gain unauthorized access to administrative functions, potentially leading to a complete site takeover. The issue is addressed in version 2.0.32.
Affected products
- bPlugins B Blocks <= 2.0.31
Timeline
- 2026-01-21: other: Reported by Abu Hurayra
- 2026-04-16: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date