Responsive Blocks <= 2.2.9 - Authenticated (Contributor+) Missing Authorization to Media Library Image Upload via Template Import REST Endpoint

Medium 4.3 CWE-862Fixed in 2.3.0
ID
WPSEC-2026-0536
Plugin
Responsive Blocks – Page Builder for Blocks & Patterns (responsive-block-editor-addons)
Affected
from 1.3.3 before 2.3.0
Remediation
Update to 2.3.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Responsive Blocks on WPSec AttackSurface
Fix released
Published

Description

The Responsive Blocks plugin for WordPress is vulnerable to unauthorized media uploads in versions up to, and including, 2.2.9 that include the block template library (1.3.3 to 1.6.3 and 1.7.8 to 2.2.9) due to a missing upload_files capability check in the template image importer. The template import REST endpoint only requires the edit_posts capability, and the importer downloads the image URLs found in the submitted pattern content and saves them as media library attachments. This makes it possible for authenticated attackers, with contributor-level access and above, to add image files fetched from URLs of their choosing to the media library, which their role is otherwise not permitted to do.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0