What the vulnerability does
01Description
Missing Authorization vulnerability in bPlugins Parallax Section block parallax-section allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Parallax Section block: from n/a through <= 1.0.9.
Explanation of Vulnerability in Simple Terms
02Summary
The Parallax Section block plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to modify site content and disrupt service. An attacker with a basic user account can bypass permission checks to alter parallax section settings and cause the site to become unavailable. Update to a version newer than 1.0.9 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify parallax section content and crash the site, even with a basic user account.
Potential impact on your site
04Site Impact
Unauthorized users can deface content and trigger denial of service without admin intervention.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., Contributor or Subscriber).
Key dates
06Disclosure timeline
December 18, 2025
CVE published
April 28, 2026
Record updated