🔐 CVE Alert

CVE-2026-3480

MEDIUM 6.5

WP Blockade <= 0.9.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'shortcode' Parameter

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. The plugin registers an admin_post action hook 'wp-blockade-shortcode-render' that maps to the render_shortcode_preview() function. This function lacks any capability check (current_user_can()) and nonce verification, allowing any authenticated user to execute arbitrary WordPress shortcodes. The function takes a user-supplied 'shortcode' parameter from $_GET, passes it through stripslashes(), and directly executes it via do_shortcode(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes, which could lead to information disclosure, privilege escalation, or other impacts depending on what shortcodes are registered on the site (e.g., shortcodes from other plugins that display sensitive data, perform actions, or include files).

CWE CWE-862
Vendor burlingtonbytes
Product wp blockade – visual page builder
Published Apr 8, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for burlingtonbytes wp blockade – visual page builder

Be the first to know when new medium vulnerabilities affecting burlingtonbytes wp blockade – visual page builder are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

burlingtonbytes / WP Blockade – Visual Page Builder
0 ≤ 0.9.14

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/3f159aac-092b-4655-9d97-a496ac01738c?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-blockade/trunk/wp-blockade.php#L393 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-blockade/tags/0.9.14/wp-blockade.php#L393 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-blockade/trunk/wp-blockade.php#L361 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-blockade/tags/0.9.14/wp-blockade.php#L361 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-blockade/trunk/wp-blockade.php#L112 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-blockade/tags/0.9.14/wp-blockade.php#L112

Credits

Youcef Hamdani