Impact
The vulnerability in the bPlugins B Blocks WordPress plugin is a missing authorization flaw that lets users access functionality they should not see. An attacker could exploit improperly configured security levels to read or modify content, settings, or other protected data, leading to potential breaches of confidentiality and integrity.
Affected Systems
All releases of the B Blocks plugin from bPlugins that are older than version 2.0.30 are vulnerable. This includes every prior release, such as 2.0.29 and earlier, across all WordPress installations that use the plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation, with the vulnerability not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the plugin’s web interface, where an attacker could send crafted HTTP requests that bypass access controls and gain unauthorized access to protected resources.
OpenCVE Enrichment