Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled, which is not the default. | |
| Title | All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-18T06:11:38.882Z
Reserved: 2026-09-10T16:05:26.098Z
Link: CVE-2026-88994
No data.
Status : Received
Published: 2026-09-18T07:16:50.790
Modified: 2026-09-18T07:16:50.790
Link: CVE-2026-88994
No data.
OpenCVE Enrichment
No data.
No weakness.
