What the vulnerability does
01Description
The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to create a new account and assign it the administrator role.
Explanation of Vulnerability in Simple Terms
02Summary
bBlocks – Essential Gutenberg Blocks & Patterns Collection versions 2.0.6 and earlier lack proper authorization checks. An unauthenticated attacker can read, modify, or delete site data without permission. This affects all installations of the plugin. Update immediately to a version newer than 2.0.6.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete site data without any authentication or user interaction.
Potential impact on your site
04Site Impact
Attackers can compromise your site's data, content, and configuration without logging in.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
August 12, 2025
CVE published
April 8, 2026
Record updated