Executive brief
The Magazine Blocks WordPress plugin, used for creating magazine and newspaper websites with customizable layouts, is vulnerable to an authorization bypass that allows lower-privileged users to demote and modify administrator-controlled templates. Attackers with contributor-level access or higher can replace site-wide header, footer, and other key page templates with malicious content, leading to website defacement, phishing attacks, and SEO spam that impacts customer trust and search visibility.
Technical details
The vulnerability is an authorization bypass in the mzb-builder-template post type registration. The plugin uses capability_type='post' for the custom post type and exposes it via the REST API without proper permission checks. The _mzb_template meta key is accessible to any user with the edit_posts capability (including Contributor-level and above), allowing these users to trigger the vulnerable save_post() hook and demote published administrator-owned templates to draft status. An authenticated attacker with contributor-level access or above can replace site-wide templates (header, footer, front page, single, archive, 404, and search) with attacker-authored content. A patch is available in versions after 1.8.6.
Affected products
- Magazine Blocks Magazine Blocks up to and including 1.8.6
Timeline
- 2026-09-18: disclosed