Junglewise Threat Intelligence

CVE-2026-57386: Kodezen LLC aBlocks privilege escalation in WordPress plugin

CVE-2026-57386 · Severity: high · CVSS 8.8 · Published 2026-07-13

Executive brief

aBlocks is a WordPress plugin used to add custom blocks and design elements to websites. A security flaw in this plugin allows users with low-level access, such as contributors, to increase their own permissions. If successfully exploited, an attacker could gain full administrative control over the website, leading to data theft, site defacement, or complete service disruption.

Technical details

An Incorrect Privilege Assignment vulnerability (CWE-266) exists in the Kodezen LLC aBlocks plugin for WordPress. The flaw allows an authenticated user with at least 'Contributor' level permissions to escalate their privileges via network requests. By exploiting this misconfiguration in how the plugin assigns or validates user roles, an attacker can gain administrative access to the WordPress environment. The vulnerability is addressed in version 2.9.1.

Affected products

  • Kodezen LLC aBlocks n/a through < 2.9.1

Timeline

  • 2026-04-24: disclosed: Reported by Evan NR to Patchstack
  • 2026-07-07: advisory: Patchstack published advisory
  • 2026-07-13: patched: NVD published date and patch confirmed in version 2.9.1

References