Impact
The CMS Blocks plugin for WordPress suffers from a missing authorization check, allowing an attacker to bypass access controls (CWE‑862). This defect can enable creation, editing, or deletion of blocks without the permissions normally required, thereby compromising the integrity and confidentiality of site content and settings.
Affected Systems
The vulnerability affects the CMS Blocks plugin developed by pankaj.sakaria. All releases up to and including version 1.1 are impacted; no information is available regarding a version that contains the fix.
Risk and Exploitability
The CVSS score of 6.5 labels the issue as moderate severity, yet the EPSS score of <1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the attack vector is inferred to be remote over HTTP/HTTPS, where an unauthenticated or low‑privileged user could send crafted requests to the plugin’s endpoints to gain unauthorized access.
OpenCVE Enrichment
EUVD