BlockSpare WP Plugin <=4.2.6 Auth Bypass by Incorrect Permission Callback
CVE-2026-1242 Published on September 19, 2026

BlockSpare - Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Creation
The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass authorization checks and create arbitrary posts.

NVD

Timeline

Disclosed

Weakness Type

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2026-1242 has been classified to as an AuthZ vulnerability or weakness.


Affected Versions

BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites: