Description
Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.
Published: 2026-07-13
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect privilege assignment flaw in the aBlocks plugin released by Kodezen LLC, allowing an attacker to elevate privileges within a WordPress site. This flaw permits a user with lower privileges to gain higher level permissions, potentially accessing or modifying content beyond their intended scope. The weakness is identified as CWE‑266, which denotes issues around incorrect privilege allocation.

Affected Systems

The aBlocks plugin from Kodezen LLC, versions from the earliest release up to, but excluding, 2.9.1, is affected on any WordPress installation that includes the plugin. No specific WordPress core versions are listed as impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity issue, while the EPSS score of less than 1% suggests a low probability of automated exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation would likely require an attacker to have or acquire some authenticated access to the WordPress admin area, or to trigger the plugin's functionality through the web interface, enabling them to leverage the privilege escalation flaw.

Generated by OpenCVE AI on July 31, 2026 at 12:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the aBlocks plugin to version 2.9.1 or later.
  • If the plugin is not essential to site functionality, uninstall or disable it entirely.
  • Review WordPress administrator roles and ensure only trusted users have elevated privileges; consider tightening role capabilities.

Generated by OpenCVE AI on July 31, 2026 at 12:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Kodezen
Kodezen ablocks
Wordpress
Wordpress wordpress
Vendors & Products Kodezen
Kodezen ablocks
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.
Title WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Kodezen Ablocks
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:39:21.418Z

Reserved: 2026-06-24T12:46:01.632Z

Link: CVE-2026-57386

cve-icon Vulnrichment

Updated: 2026-07-13T13:59:07.112Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment