MEDIUM
blockspare
CVE published 2026-09-19
CVE-2026-1242
The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass authorization checks and create arbitrary posts. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Defenders should pri [truncated]