Authorization Bypass Vulnerability in Cozy Blocks for WordPress
CVE-2026-19948
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-19948?
The Cozy Blocks – Page Builder plugin for WordPress is susceptible to an authorization bypass, affecting all versions up to 2.2.17. The vulnerability arises from the plugin's failure to ensure proper user authorization for action execution, enabling unauthenticated attackers to access sensitive data related to WooCommerce products. Attackers can exploit this flaw to retrieve product information—including names, prices, descriptions, image URLs, permalinks, stock statuses, and product types—of draft and hidden items that are not meant for public visibility. The issue is exacerbated by the fact that sidebarNonce values are rendered in public HTML without adequate security checks, allowing unauthorized individuals to leverage these values to circumvent authentication requirements.
Affected Version(s)
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates 0 <= 2.2.17