Authorization Bypass in Magazine Blocks Plugin for WordPress by Vendor
CVE-2026-75017
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-75017?
The Magazine Blocks Plugin for WordPress is vulnerable to an authorization bypass issue, allowing authenticated users with contributor-level access and higher to demote administrator-owned templates to draft status. This vulnerability arises from improper verification of user permissions when accessing the mzb-builder-template post type exposed via the REST API. As a result, attackers can replace legitimate content with their own, leading to site-wide defacement, phishing threats, and potential SEO spam, thus compromising the integrity and security of affected sites.
Affected Version(s)
Magazine Blocks β Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid 0 <= 1.8.6