# Responsive Blocks <= 2.2.9 - Authenticated (Contributor+) Missing Authorization to Media Library Image Upload via Template Import REST Endpoint

- **ID:** WPSEC-2026-0536
- **Plugin:** Responsive Blocks – Page Builder for Blocks & Patterns (`responsive-block-editor-addons`), https://wordpress.org/plugins/responsive-block-editor-addons/
- **Affected versions:** from 1.3.3 before 2.3.0
- **Fixed in:** 2.3.0 (Update to 2.3.0 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/responsive-block-editor-addons
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0536/

## Description

The Responsive Blocks plugin for WordPress is vulnerable to unauthorized media uploads in versions up to, and including, 2.2.9 that include the block template library (1.3.3 to 1.6.3 and 1.7.8 to 2.2.9) due to a missing upload_files capability check in the template image importer. The template import REST endpoint only requires the edit_posts capability, and the importer downloads the image URLs found in the submitted pattern content and saves them as media library attachments. This makes it possible for authenticated attackers, with contributor-level access and above, to add image files fetched from URLs of their choosing to the media library, which their role is otherwise not permitted to do.

## References

- https://wpsec.com/vuln/WPSEC-2026-0536/
- https://plugins.svn.wordpress.org/responsive-block-editor-addons/tags/2.3.0/
- https://wordpress.org/plugins/responsive-block-editor-addons/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0536/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
