Junglewise Threat Intelligence

CVE-2026-88994: All Bootstrap Blocks local file inclusion via lightspeed

CVE-2026-88994 · Severity: medium · CVSS 6.6 · Published 2026-09-18

Executive brief

The All Bootstrap Blocks WordPress plugin is a Gutenberg block editor extension that allows users to create page layouts. A vulnerability in versions up to 1.3.31 enables users with contributor-level access to include and execute arbitrary local files on the server, potentially exposing sensitive data or executing malicious code. The flaw only affects sites where the optional Lightspeed subsystem is enabled.

Technical details

The plugin fails to validate a block attribute before using it to construct a filesystem path that is included at render time, resulting in a local file inclusion (LFI) vulnerability. An authenticated attacker with contributor-level or higher privileges can manipulate the block attribute to traverse the filesystem and include arbitrary local files. If the included file contains PHP code, that code will be executed in the context of the web server. Exploitation requires the plugin's Lightspeed subsystem to be explicitly enabled; it is disabled by default. No patch is currently available.

Affected products

  • All Bootstrap Blocks All Bootstrap Blocks through 1.3.31

Timeline

  • 2026-09-16: disclosed
  • 2026-09-18: advisory

References