{
 "id": "WPSEC-2026-0536",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0536/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0536/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0536/index.md",
 "title": "Responsive Blocks <= 2.2.9 - Authenticated (Contributor+) Missing Authorization to Media Library Image Upload via Template Import REST Endpoint",
 "description": "The Responsive Blocks plugin for WordPress is vulnerable to unauthorized media uploads in versions up to, and including, 2.2.9 that include the block template library (1.3.3 to 1.6.3 and 1.7.8 to 2.2.9) due to a missing upload_files capability check in the template image importer. The template import REST endpoint only requires the edit_posts capability, and the importer downloads the image URLs found in the submitted pattern content and saves them as media library attachments. This makes it possible for authenticated attackers, with contributor-level access and above, to add image files fetched from URLs of their choosing to the media library, which their role is otherwise not permitted to do.",
 "plugin": {
  "slug": "responsive-block-editor-addons",
  "name": "Responsive Blocks",
  "full_name": "Responsive Blocks – Page Builder for Blocks & Patterns",
  "wordpress_org": "https://wordpress.org/plugins/responsive-block-editor-addons/",
  "advisories_url": "https://wpsec.com/vuln/plugin/responsive-block-editor-addons/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/responsive-block-editor-addons"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.3.3",
    "from_inclusive": true,
    "to": "2.3.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.3.3 before 2.3.0"
  ]
 },
 "introduced_in": "1.3.3",
 "fixed_in": "2.3.0",
 "remediation": "Update to 2.3.0 or later.",
 "fix_released": "2026-10-06T11:41:03+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-07T12:34:58.880547+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0536/",
  "https://plugins.svn.wordpress.org/responsive-block-editor-addons/tags/2.3.0/",
  "https://wordpress.org/plugins/responsive-block-editor-addons/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/responsive-block-editor-addons",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}