CVE-2026-19948
Last modified
CVE-2026-19948 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve the name, price, short description, image URL, permalink, stock status, and product type of draft, pending, private, and catalog-hidden WooCommerce products not intended to be publicly visible. The sidebarNonce value is emitted unconditionally into public page HTML by multiple block renderers with no login gate, allowing unauthenticated visitors to harvest a valid nonce and pass the only authentication check in the handler.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| cozythemes | Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates | <= 2.2.17 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-19948?
How severe is CVE-2026-19948?
How do I fix CVE-2026-19948?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19941An inapplicable NSEC record may be accepted by a `named` res…5.9
- CVE-2026-19942The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, …8.1
- CVE-2026-19943The Gutenverse – WordPress Blocks, Page Builder & Site Edito…6.4
- CVE-2026-19944The WP Crowdfunding plugin for WordPress is vulnerable to ge…4.9
- CVE-2026-19945The WP Crowdfunding plugin for WordPress is vulnerable to St…6.4
- CVE-2026-19946The Awesome Support plugin for WordPress is vulnerable to Mi…4.3
- CVE-2026-19949The All-in-One WP Migration and Backup plugin for WordPress …8.8
- CVE-2026-1995In versions before 7.0.0.64, IDrive’s id_service.exe process…7.8
- CVE-2026-19952The Frontend Admin by DynamiApps plugin for WordPress is vul…7.5
- CVE-2026-19953URI versions before 5.36 for Perl encode non-NFC host names …6.5
- CVE-2026-19955A vulnerability was detected in TrailDB 0.6. Impacted is the…3.5
- CVE-2026-19956A vulnerability has been found in gomarble-ai facebook-ads-m…6.3
Are you affected by CVE-2026-19948?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
