Impact
The BlockSpare plugin for WordPress contains an authorization bypass flaw caused by incorrect logic in its permission callback, where an AND operator was used instead of an OR. This flaw allows authenticated users with a Subscriber role or higher to bypass the intended access checks and create arbitrary posts. The primary impact is the ability to publish or modify content on a site without proper authorization. The weakness is classified as authorization bypass through a user‑controlled condition.
Affected Systems
The vulnerability affects the BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites WordPress plugin in all releases up to and including version 4.2.6. WordPress administrators installing or using these plugin versions are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely in the short term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers need only authenticated access at the Subscriber level or higher, so the attack vector is a trusted user, not remote code execution. An attacker could potentially flood the site with unwanted posts, replace legitimate content, or serve malicious links, harming the site's integrity and user trust.
OpenCVE Enrichment