Impact
The vulnerability is an incorrect privilege assignment flaw in the aBlocks plugin released by Kodezen LLC, allowing an attacker to elevate privileges within a WordPress site. This flaw permits a user with lower privileges to gain higher level permissions, potentially accessing or modifying content beyond their intended scope. The weakness is identified as CWE‑266, which denotes issues around incorrect privilege allocation.
Affected Systems
The aBlocks plugin from Kodezen LLC, versions from the earliest release up to, but excluding, 2.9.1, is affected on any WordPress installation that includes the plugin. No specific WordPress core versions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity issue, while the EPSS score of less than 1% suggests a low probability of automated exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation would likely require an attacker to have or acquire some authenticated access to the WordPress admin area, or to trigger the plugin's functionality through the web interface, enabling them to leverage the privilege escalation flaw.
OpenCVE Enrichment