
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14360 is a Missing Authorization (Broken Access Control) vulnerability in the Kaira Blockons WordPress plugin that allows unauthenticated attackers to access functionality not properly constrained by ACLs. It affects Blockons versions up to and including 1.2.19 (initially disclosed as affecting through 1.2.15, later updated to 1.2.19 in April 2026). The vulnerability was reported by MD ISMAIL on August 13, 2025, and published by Patchstack on January 8, 2026. It carries a CVSS v3.1 base score of 7.5 (High), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks — such as capability checks or nonce token validation — before executing privileged functionality. This allows an unauthenticated network attacker to invoke restricted plugin functions directly, bypassing WordPress access control mechanisms. The attack requires no user interaction, no special privileges, and low complexity, making it trivially exploitable over the network (Patchstack).
Successful exploitation allows an unauthenticated attacker to access sensitive plugin functionality that should be restricted to privileged users. The primary impact is a high confidentiality risk (C:H), with the Patchstack-assigned CVSS vector indicating no direct integrity or availability impact. However, depending on the specific unprotected functionality exposed, attackers could potentially read sensitive configuration data or site information, and Patchstack notes this class of vulnerability is commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity (Patchstack).
No public proof-of-concept exploit code has been identified, and there is no confirmed evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.017%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies it as high priority and notes that broken access control vulnerabilities of this type are frequently leveraged in mass-exploit campaigns against WordPress plugins (Patchstack).
As of the time of publication, no official patch from the plugin developer (Kaira) is available for the Blockons plugin. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators should consider deactivating and removing the Blockons plugin until a patched version (above 1.2.19) becomes available, or deploy a web application firewall solution such as Patchstack to mitigate the risk (Patchstack).
The vulnerability received brief coverage on security-focused social media accounts, including mentions on Mastodon via TheHackerWire shortly after disclosure in January 2026. No significant vendor statements or notable researcher commentary beyond the Patchstack advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."