PatchSiren

blockspare CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM blockspare CVE published 2026-09-19

CVE-2026-1242

The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass authorization checks and create arbitrary posts. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Defenders should pri [truncated]