Description
Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Blocks: from n/a through <= 1.8.3.
Published: 2026-04-15
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to plugin features enabling privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The BlockArt Magazine Blocks plugin contains a missing authorization check that allows users to exploit incorrectly configured access control levels. This flaw permits an attacker to perform actions restricted to administrators, such as altering plugin settings or manipulating content blocks. The vulnerability is classified as CWE‑862, indicating broken access control, and is not known to provide arbitrary code execution but does compromise site integrity and operational control.

Affected Systems

The issue applies to all installations of BlockArt Magazine Blocks plugin version 1.8.3 and earlier. WordPress sites that have not yet upgraded to a patched release are vulnerable. No other vendors or products are listed in the CNA data.

Risk and Exploitability

The CVSS score is 4.3 and the EPSS score is < 1 %. The vulnerability is not listed in CISA’s KEV catalog. Although no exploitation examples are publicly documented, the flaw could allow privilege escalation within a WordPress site if an attacker has access to a user account that can reach the plugin’s administrative interfaces. Based on the description, the likely attack vector involves an authenticated user engaging with the plugin’s management pages, as the missing authorization check permits actions that should be restricted to administrators. The potential impact includes unauthorized modification of plugin settings or content blocks, compromising site integrity and operational control.

Generated by OpenCVE AI on April 15, 2026 at 22:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Magazine Blocks plugin to the latest publicly released version
  • Configure all plugin administrative pages to enforce the Administrator role
  • Apply firewall or .htaccess rules that restrict direct access to plugin configuration URLs to trusted IPs or authenticated administrators
  • Audit any custom theme or plugin code that calls Magazine Blocks functions and add explicit permission checks to ensure only authorized roles may execute privileged actions
  • Monitor site logs for unauthorized attempts to access plugin settings

Generated by OpenCVE AI on April 15, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Blockart
Blockart magazine Blocks
Wordpress
Wordpress wordpress
Vendors & Products Blockart
Blockart magazine Blocks
Wordpress
Wordpress wordpress

Wed, 15 Apr 2026 10:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Blocks: from n/a through <= 1.8.3.
Title WordPress Magazine Blocks plugin <= 1.8.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Blockart Magazine Blocks
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-15T15:36:33.255Z

Reserved: 2026-04-15T09:19:20.453Z

Link: CVE-2026-40728

cve-icon Vulnrichment

Updated: 2026-04-15T15:35:52.202Z

cve-icon NVD

Status : Received

Published: 2026-04-15T11:16:35.560

Modified: 2026-04-15T16:16:37.867

Link: CVE-2026-40728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T22:30:16Z

Weaknesses