Description
Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.28.
Published: 2025-08-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the All Bootstrap Blocks WordPress plugin that allows attackers to exploit incorrectly configured access control security levels. An attacker who can trigger the plugin’s functionality may be able to perform actions normally restricted to higher‑privilege users, leading to unauthorized data modification or disclosure. The weakness is identified as a classic privilege escalation due to improper role checks, which could compromise confidentiality, integrity, or availability of WordPress content. The official CVE description confirms that the issue is limited to the plugin itself, without indicating broader system damage.

Affected Systems

All users of the All Bootstrap Blocks plugin up to and including version 1.3.28 are affected. The vendor name is All Bootstrap Blocks, and any WordPress installation that has this plugin installed and is running a version ≤ 1.3.28 may be vulnerable. No specific operating system or platform constraints are listed, so the weakness applies broadly to any environment where the plugin is used.

Risk and Exploitability

The CVSS score of 6.5 places this vulnerability in the medium severity range, while the EPSS score of < 1% indicates a low current probability of exploitation. The vulnerability is not featured in CISA’s KEV catalog. Because the flaw resides solely in the plugin’s access control logic, an attacker need only have any user account or be able to craft requests that consume the plugin’s exposed endpoints. The likely attack vector is through the normal WordPress front‑end or admin interface, meaning that exploitation can occur without privileged remote access or additional software. Once the attacker bypasses the authorization check, they may gain the ability to create edit, or delete content, thereby violating the principle of least privilege for the site’s administrators.

Generated by OpenCVE AI on April 30, 2026 at 07:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the All Bootstrap Blocks plugin to a version newer than 1.3.28. The vendor recommends applying the latest release to patch the authorization flaw.
  • If an upgrade cannot be performed immediately, disable the All Bootstrap Blocks plugin so that its protected endpoints are no longer available or reachable from the site.
  • Use a web application firewall or access‑control rules to block unauthenticated or unauthorized requests to the plugin’s endpoints until the upgrade is performed.

Generated by OpenCVE AI on April 30, 2026 at 07:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25972 Missing Authorization vulnerability in Miles All Bootstrap Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects All Bootstrap Blocks: from n/a through 1.3.28.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Miles All Bootstrap Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects All Bootstrap Blocks: from n/a through 1.3.28. Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.28.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Thu, 28 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Miles All Bootstrap Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects All Bootstrap Blocks: from n/a through 1.3.28.
Title WordPress All Bootstrap Blocks Plugin <= 1.3.28 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:06:51.788Z

Reserved: 2025-07-28T10:56:33.522Z

Link: CVE-2025-54733

cve-icon Vulnrichment

Updated: 2025-08-28T13:39:28.514Z

cve-icon NVD

Status : Deferred

Published: 2025-08-28T13:16:08.903

Modified: 2026-04-23T15:32:54.437

Link: CVE-2025-54733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T07:45:26Z

Weaknesses