Vulnerability in BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites — CVE-2026-1242
MediumSeverity
—Estimated exploit probability
10,000+ sitesInstalls
Not publishedFixed in
What to do now
No fix has been published yet. Consider disabling BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites for now, or moving to an alternative.
Affected versions
- Everything up to and including 4.2.6
Affected: BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites (plugin, blockspare)
What the vulnerability is
The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass authorization checks and create arbitrary posts.