Responsive Blocks <= 2.2.9 - Authenticated (Contributor+) Missing Authorization to Media Library Image Upload via Template Import REST Endpoint
- ID
- WPSEC-2026-0536
- Plugin
- Responsive Blocks – Page Builder for Blocks & Patterns (responsive-block-editor-addons)
- Affected
- from 1.3.3 before 2.3.0
- Remediation
- Update to 2.3.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Responsive Blocks on WPSec AttackSurface
- Fix released
- Published
Description
The Responsive Blocks plugin for WordPress is vulnerable to unauthorized media uploads in versions up to, and including, 2.2.9 that include the block template library (1.3.3 to 1.6.3 and 1.7.8 to 2.2.9) due to a missing upload_files capability check in the template image importer. The template import REST endpoint only requires the edit_posts capability, and the importer downloads the image URLs found in the submitted pattern content and saves them as media library attachments. This makes it possible for authenticated attackers, with contributor-level access and above, to add image files fetched from URLs of their choosing to the media library, which their role is otherwise not permitted to do.
References
- https://wpsec.com/vuln/WPSEC-2026-0536/
- https://plugins.svn.wordpress.org/responsive-block-editor-addons/tags/2.3.0/
- https://wordpress.org/plugins/responsive-block-editor-addons/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS