cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formagazine-blocks magazine-blocks

Direction: descending
Sep 19, 2026

Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2026-75017

CVE, Research URL

CVE-2026-75017

Date
Sep 18, 2026
Research Description
The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to demote administrator-owned published builder templates (header, footer, front page, single, archive, 404, and search) to draft status and replace them with attacker-authored block content rendered site-wide, enabling defacement, phishing, and SEO spam. This is possible because the mzb-builder-template post type is registered with capability_type='post' and exposed via the REST API, and the _mzb_template meta key is accessible to any user with edit_posts capability, meaning Contributor-level users and above can trigger the vulnerable save_post() hook.
Affected versions
max 1.8.7.
Status
vulnerable

Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2026-75016

CVE, Research URL

CVE-2026-75016

Date
Sep 18, 2026
Research Description
The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, 1.8.6. This is due to insufficient input sanitization and output escaping in the NewsTicker::render() method, which concatenates the clientId block attribute into an HTML class attribute without applying esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.8.7.
Status
vulnerable
Aug 26, 2026
Jul 01, 2026
Apr 17, 2026

Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2026-40728

CVE, Research URL

CVE-2026-40728

Date
Apr 15, 2026
Research Description
Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Blocks: from n/a through <= 1.8.3.
Affected versions
max 1.8.4.
Status
vulnerable
Jan 03, 2025

Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-56258

CVE, Research URL

CVE-2024-56258

Date
Jan 02, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlockArt Magazine Blocks magazine-blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through <= 1.3.20.
Affected versions
max 1.3.21.
Status
vulnerable
Oct 27, 2024

Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-50429

CVE, Research URL

CVE-2024-50429

Date
Oct 29, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlockArt Magazine Blocks magazine-blocks allows DOM-Based XSS.This issue affects Magazine Blocks: from n/a through <= 1.3.15.
Affected versions
max 1.3.18.
Status
vulnerable
Oct 03, 2024

Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-9218

CVE, Research URL

CVE-2024-9218

Date
Oct 02, 2024
Research Description
The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.14. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.3.15.
Status
vulnerable
Jun 07, 2024

Magazine Blocks – Blog Designer, Magazine &amp; Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid # CVE-2024-34760

CVE, Research URL

CVE-2024-34760

Date
May 16, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockart Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.6.
Affected versions
max 1.3.7.
Status
vulnerable