Impact
The vulnerability allows an attacker with contributor or higher privileges to demote published builder templates to draft status and replace them with attacker‑authored block content, effectively defacing the site, executing phishing attacks, or inserting SEO spam. The flaw originates from an insufficient capability check on the mzb-builder-template custom post type, which is registered with capability_type='post' and exposed through the REST API. As a result, any authenticated user with edit_posts capability can trigger the vulnerable save_post() hook to modify template content site‑wide.
Affected Systems
WordPress sites utilizing the "Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid" plugin version 1.8.6 or earlier are affected. No newer versions are known to contain the issue, and updated releases are recommended.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity level, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The flaw is not listed in the CISA KEV catalog. Attackers must be authenticated, but contributors and higher roles are sufficient, and the REST API endpoint can be accessed over HTTP or HTTPS, making the attack vector network‑based and relatively straightforward for threatened users. The vulnerability’s reliance on an unauthorized capability check (CWE‑862) underscores its potential for widespread impact across sites that rely on the affected plugin.
OpenCVE Enrichment