The Magazine Blocks plugin for WordPress has an authorization bypass vulnerability allowing contributors and above to demote and replace administrator-owned published templates, enabling site-wide defacement, phishing, and SEO spam. This vulnerability exists due to improper authorization checks in the plugin, allowing authenticated attackers with contributor-level access to perform actions they shouldn't. [truncated]
The Magazine Blocks plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. Authenticated attackers with contributor-level access can inject web scripts that execute when users access injected pages. This vulnerability allows for potential malicious script execution, impacting site integrity and user secur [truncated]