๐Ÿ” CVE Alert

CVE-2026-88994

MEDIUM 6.6

All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes

CVSS Score
6.6
EPSS Score
0.0%
EPSS Percentile
0th

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled, which is not the default.

Vendor unknown
Product all bootstrap blocks
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown all bootstrap blocks

Be the first to know when new medium vulnerabilities affecting unknown all bootstrap blocks are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / All Bootstrap Blocks
1.3.20 โ‰ค 1.3.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/55b1f0b1-dc15-45d4-beb2-4d1d7a9fe3dd/

Credits

Revanth Hari Narayana Matte WPScan